CVE-2009-4112
Publication date 30 November 2009
Last updated 24 July 2024
Ubuntu priority
Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands.
Notes
jdstrand
per Debian, not a security issue because the admin is expected to be able to define such Data Input Methods.