BUG: SNMP passwords processed unescaped

Post general support questions here that do not specifically fall into the Linux or Windows categories.

Moderators: Developers, Moderators

Post Reply
philipp123
Posts: 2
Joined: Thu Dec 04, 2014 6:52 am

BUG: SNMP passwords processed unescaped

Post by philipp123 »

SNMPv3 passwords are passed by Cacti to mysql unescaped. So if I wish to use a single-quote character (') in my password, it will break data collection and generate a mysql syntax error. Please would you kindly fix.

Thanks,

Philip
User avatar
BSOD2600
Cacti Moderator
Posts: 12171
Joined: Sat May 08, 2004 12:44 pm
Location: USA

Re: BUG: SNMP passwords processed unescaped

Post by BSOD2600 »

What version of Cacti, OS, mysql, and php?

If not already on 0.8.8c, please upgrade and try to repro again. If successful, file a bug: http://www.cacti.net/bugs.php
philipp123
Posts: 2
Joined: Thu Dec 04, 2014 6:52 am

Re: BUG: SNMP passwords processed unescaped

Post by philipp123 »

Cacti Version 0.8.8a
PHP Version 5.3.3
mysql Server version: 5.1.61

I've worked-around it by changing to a different password, but it's exactly the kind of thing that would catch the unwary.
User avatar
BSOD2600
Cacti Moderator
Posts: 12171
Joined: Sat May 08, 2004 12:44 pm
Location: USA

Re: BUG: SNMP passwords processed unescaped

Post by BSOD2600 »

thanks for the report.

you do know those versions of php/mysql are EOL and filled with vulnerabilities, right? ;)
cigamit
Developer
Posts: 3369
Joined: Thu Apr 07, 2005 3:29 pm
Location: B/CS Texas
Contact:

Re: BUG: SNMP passwords processed unescaped

Post by cigamit »

BSOD2600 wrote:you do know those versions of php/mysql are EOL and filled with vulnerabilities, right? ;)
PHP 5.3.3 on Redhat/Centos will receive backported security fixes until Nov 2020. :)
User avatar
BSOD2600
Cacti Moderator
Posts: 12171
Joined: Sat May 08, 2004 12:44 pm
Location: USA

Re: BUG: SNMP passwords processed unescaped

Post by BSOD2600 »

Really?! bah! Time to stop living in the past.
cigamit
Developer
Posts: 3369
Joined: Thu Apr 07, 2005 3:29 pm
Location: B/CS Texas
Contact:

Re: BUG: SNMP passwords processed unescaped

Post by cigamit »

BSOD2600 wrote:Really?! bah! Time to stop living in the past.
I will probably stay with PHP 5.3.3 until 2020 (or find another repo). I refuse to upgrade to Centos 7, since it contains systemd.
Post Reply

Who is online

Users browsing this forum: No registered users and 4 guests