CVE

Id
13355  
CVE No.
CVE-2005-2149  
Status
Candidate  
Description
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.  
Phase
Assigned (20050706)  
Votes
None (candidate not yet proposed)  
Comments