From ba60752839b2228fd450b45df634d5bc82672dde Mon Sep 17 00:00:00 2001 From: Grzegorz Sterniczuk Date: Wed, 21 Nov 2007 11:06:34 +0000 Subject: [PATCH 1/1] - new security patch for cacti 0.8.6j Changed files: sec_sql_injection-0.8.6j.patch -> 1.1 --- sec_sql_injection-0.8.6j.patch | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 sec_sql_injection-0.8.6j.patch diff --git a/sec_sql_injection-0.8.6j.patch b/sec_sql_injection-0.8.6j.patch new file mode 100644 index 0000000..37b2838 --- /dev/null +++ b/sec_sql_injection-0.8.6j.patch @@ -0,0 +1,14 @@ +diff -ruBbdN cacti-0.8.6j/include/top_graph_header.php cacti-0.8.6j-patched/include/top_graph_header.php +--- cacti-0.8.6j/include/top_graph_header.php 2007-01-17 19:23:10.000000000 -0500 ++++ cacti-0.8.6j-patched/include/top_graph_header.php 2007-11-03 12:53:46.000000000 -0400 +@@ -27,6 +27,10 @@ + $using_guest_account = false; + $show_console_tab = true; + ++/* ================= input validation ================= */ ++input_validate_input_number(get_request_var_request("local_graph_id")); ++/* ==================================================== */ ++ + if (read_config_option("global_auth") == "on") { + /* at this point this user is good to go... so get some setting about this + user and put them into variables to save excess SQL in the future */ -- 2.44.0