SNMPv3 passwords are passed by Cacti to mysql unescaped. So if I wish to use a single-quote character (') in my password, it will break data collection and generate a mysql syntax error. Please would you kindly fix.
Thanks,
Philip
BUG: SNMP passwords processed unescaped
Moderators: Developers, Moderators
Re: BUG: SNMP passwords processed unescaped
What version of Cacti, OS, mysql, and php?
If not already on 0.8.8c, please upgrade and try to repro again. If successful, file a bug: http://www.cacti.net/bugs.php
If not already on 0.8.8c, please upgrade and try to repro again. If successful, file a bug: http://www.cacti.net/bugs.php
| Scripts: Monitor processes | RFC1213 MIB | DOCSIS Stats | Dell PowerEdge | Speedfan | APC UPS | DOCSIS CMTS | 3ware | Motorola Canopy |
| Guides: Windows Install | [HOWTO] Debug Windows NTFS permission problems |
| Tools: Windows All-in-one Installer |
-
- Posts: 2
- Joined: Thu Dec 04, 2014 6:52 am
Re: BUG: SNMP passwords processed unescaped
Cacti Version 0.8.8a
PHP Version 5.3.3
mysql Server version: 5.1.61
I've worked-around it by changing to a different password, but it's exactly the kind of thing that would catch the unwary.
PHP Version 5.3.3
mysql Server version: 5.1.61
I've worked-around it by changing to a different password, but it's exactly the kind of thing that would catch the unwary.
Re: BUG: SNMP passwords processed unescaped
thanks for the report.
you do know those versions of php/mysql are EOL and filled with vulnerabilities, right?
you do know those versions of php/mysql are EOL and filled with vulnerabilities, right?
| Scripts: Monitor processes | RFC1213 MIB | DOCSIS Stats | Dell PowerEdge | Speedfan | APC UPS | DOCSIS CMTS | 3ware | Motorola Canopy |
| Guides: Windows Install | [HOWTO] Debug Windows NTFS permission problems |
| Tools: Windows All-in-one Installer |
Re: BUG: SNMP passwords processed unescaped
PHP 5.3.3 on Redhat/Centos will receive backported security fixes until Nov 2020.BSOD2600 wrote:you do know those versions of php/mysql are EOL and filled with vulnerabilities, right?
Re: BUG: SNMP passwords processed unescaped
Really?! bah! Time to stop living in the past.
| Scripts: Monitor processes | RFC1213 MIB | DOCSIS Stats | Dell PowerEdge | Speedfan | APC UPS | DOCSIS CMTS | 3ware | Motorola Canopy |
| Guides: Windows Install | [HOWTO] Debug Windows NTFS permission problems |
| Tools: Windows All-in-one Installer |
Re: BUG: SNMP passwords processed unescaped
I will probably stay with PHP 5.3.3 until 2020 (or find another repo). I refuse to upgrade to Centos 7, since it contains systemd.BSOD2600 wrote:Really?! bah! Time to stop living in the past.
Who is online
Users browsing this forum: No registered users and 4 guests