graph.php security fixed

Anything that you think should be in Cacti.

Moderators: Developers, Moderators

Post Reply
nocmanager
Posts: 4
Joined: Tue Jan 21, 2003 5:42 pm

graph.php security fixed

Post by nocmanager »

I noticed that when you access CACTI with http://x.x.x.x/cacti/graph.php?rraid=al ... id=some_id where som_id is a valid ID from rrd_graph table, then you can see the graph itself without any authorisation. I removed guest user but it didn't help. So, you can walk all numbers from 1 to infinity and actualy see all graphs in the system.
aratux(guest)

Post by aratux(guest) »

Believe me, that doesn't happen with me.
Mostly you use an old version.
When I try what you have said, I get access denied message.

Regards
Mohamed Eldesoky
nocmanager
Posts: 4
Joined: Tue Jan 21, 2003 5:42 pm

Post by nocmanager »

Yes, I found out when it happened. When I removed guest user completely I could access graphs in this way, so it is not adviced to remove guest user, only to take all privileges from him, then it works fine.
Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests