You can subscribe to this list here.
| 2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
(48) |
Dec
(33) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2003 |
Jan
(24) |
Feb
(22) |
Mar
(30) |
Apr
(17) |
May
(28) |
Jun
(132) |
Jul
(11) |
Aug
(17) |
Sep
(59) |
Oct
(36) |
Nov
(90) |
Dec
(37) |
| 2004 |
Jan
(74) |
Feb
(65) |
Mar
(69) |
Apr
(33) |
May
(48) |
Jun
(38) |
Jul
(32) |
Aug
(66) |
Sep
(61) |
Oct
(129) |
Nov
(62) |
Dec
(68) |
| 2005 |
Jan
(126) |
Feb
(40) |
Mar
(91) |
Apr
(50) |
May
(83) |
Jun
(86) |
Jul
(47) |
Aug
(41) |
Sep
(197) |
Oct
(88) |
Nov
(103) |
Dec
(58) |
| 2006 |
Jan
(84) |
Feb
(130) |
Mar
(127) |
Apr
(98) |
May
(92) |
Jun
(64) |
Jul
(141) |
Aug
(135) |
Sep
(77) |
Oct
(122) |
Nov
(95) |
Dec
(45) |
| 2007 |
Jan
(71) |
Feb
(41) |
Mar
(48) |
Apr
(82) |
May
(70) |
Jun
(65) |
Jul
(49) |
Aug
(25) |
Sep
(54) |
Oct
(52) |
Nov
(62) |
Dec
(49) |
| 2008 |
Jan
(64) |
Feb
(107) |
Mar
(37) |
Apr
(20) |
May
(39) |
Jun
(49) |
Jul
(100) |
Aug
(19) |
Sep
(84) |
Oct
(46) |
Nov
(75) |
Dec
(42) |
| 2009 |
Jan
(63) |
Feb
(108) |
Mar
(34) |
Apr
(28) |
May
(18) |
Jun
(65) |
Jul
(53) |
Aug
(52) |
Sep
(36) |
Oct
(102) |
Nov
(36) |
Dec
(38) |
| 2010 |
Jan
(44) |
Feb
(33) |
Mar
(33) |
Apr
(20) |
May
(11) |
Jun
(100) |
Jul
(42) |
Aug
(57) |
Sep
(65) |
Oct
(29) |
Nov
(42) |
Dec
(83) |
| 2011 |
Jan
(30) |
Feb
(14) |
Mar
(24) |
Apr
(3) |
May
(20) |
Jun
(17) |
Jul
(38) |
Aug
(21) |
Sep
(53) |
Oct
(46) |
Nov
(35) |
Dec
(48) |
| 2012 |
Jan
(58) |
Feb
(13) |
Mar
(50) |
Apr
(48) |
May
(44) |
Jun
(11) |
Jul
(15) |
Aug
(25) |
Sep
(27) |
Oct
(17) |
Nov
(41) |
Dec
(19) |
| 2013 |
Jan
(16) |
Feb
(22) |
Mar
(29) |
Apr
(25) |
May
(28) |
Jun
(14) |
Jul
(15) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(4) |
Dec
(13) |
| 2014 |
Jan
(15) |
Feb
(8) |
Mar
(9) |
Apr
(10) |
May
|
Jun
(11) |
Jul
(4) |
Aug
(10) |
Sep
(1) |
Oct
(10) |
Nov
(4) |
Dec
(8) |
| 2015 |
Jan
(7) |
Feb
(6) |
Mar
(13) |
Apr
(1) |
May
(5) |
Jun
(6) |
Jul
(8) |
Aug
(5) |
Sep
(1) |
Oct
(6) |
Nov
(2) |
Dec
(11) |
| 2016 |
Jan
(7) |
Feb
(7) |
Mar
(6) |
Apr
|
May
(2) |
Jun
(1) |
Jul
|
Aug
|
Sep
(1) |
Oct
(2) |
Nov
|
Dec
|
| 2017 |
Jan
(3) |
Feb
(5) |
Mar
(16) |
Apr
(9) |
May
(3) |
Jun
(3) |
Jul
(8) |
Aug
(7) |
Sep
(5) |
Oct
(6) |
Nov
(1) |
Dec
(1) |
| 2018 |
Jan
(9) |
Feb
(3) |
Mar
(3) |
Apr
(2) |
May
(1) |
Jun
(5) |
Jul
|
Aug
|
Sep
|
Oct
(13) |
Nov
(4) |
Dec
|
| 2019 |
Jan
(19) |
Feb
(7) |
Mar
(1) |
Apr
(2) |
May
|
Jun
(1) |
Jul
(1) |
Aug
|
Sep
(4) |
Oct
|
Nov
|
Dec
(4) |
| 2020 |
Jan
|
Feb
(1) |
Mar
(1) |
Apr
(2) |
May
(1) |
Jun
|
Jul
(2) |
Aug
(7) |
Sep
(1) |
Oct
(3) |
Nov
(2) |
Dec
|
| 2021 |
Jan
|
Feb
|
Mar
|
Apr
|
May
(4) |
Jun
|
Jul
(2) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2022 |
Jan
|
Feb
(3) |
Mar
(1) |
Apr
(2) |
May
(2) |
Jun
|
Jul
|
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(16) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2024 |
Jan
|
Feb
|
Mar
|
Apr
(13) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(2) |
Dec
|
| S | M | T | W | T | F | S |
|---|---|---|---|---|---|---|
|
|
|
|
1
|
2
|
3
(2) |
4
|
|
5
|
6
|
7
(1) |
8
(3) |
9
|
10
|
11
|
|
12
|
13
(1) |
14
(4) |
15
(2) |
16
|
17
|
18
|
|
19
|
20
(1) |
21
|
22
(1) |
23
|
24
|
25
|
|
26
|
27
|
28
(1) |
29
|
30
|
31
|
|
|
From: Tony R. <tr...@ca...> - 2017-03-28 03:06:54
|
*** Release of Cacti 1.1.1 *** Special thanks to all that have helped by contributing code and reporting issues on GitHub! We would not be where we are today without the help. Let's continue to grow the Cacti community! For additional details check out the README located on GitHub. https://github.com/Cacti/cacti/blob/develop/README.md *** Contribute *** Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests! https://github.com/cacti/ *** Cacti Change Log *** issue#457: Continued LDAP issues with initial user creation issue#461: The function escapeshell arg not appropriate on Windows issue#462: LDAP authorization issues: group membership check broken for 'Group Member Type' = 'Username' issue#464: Change default batch spike removal limits for standard deviation and variance issue#465: Less than sign inside items and labels of graph break graph issue#466: Call to member function row() on a non-object in lib/snmpagent.php issue#467: Reduce the number of queries in log function issue#472: Schema changes to improve performance issue#485: When editing a device, the ping status was not always returned issue: Back button issues due to syntax problems in JavaScript issue: Zoom periodically would loose it's crosshairs after zooming issue: Zoom would zoom out into the future even when disabled issue: Fixing lite corruption in graph_templates_item table feature: Make SpikeKill options more consistent feature#459: Add variable date time option to report mail subject feature#460: Add external_id to host variables feature#469: Change re-index method of Data Query from Device edit feature: Support generalized date format approach in the GUI feature: Use localStorage over a Cookie for Zoom setting storage feature: Fully implement 'Remove Orphans' from Package import process *** Reporting Issues *** http://www.cacti.net/issues.php *** Download Cacti *** http://www.cacti.net/download_cacti.php *** Download Spine *** http://www.cacti.net/spine_download.php Thanks! The Cacti Group |
|
From: <emm...@if...> - 2017-03-22 10:54:27
|
Hi, i wrote plugins for Cacti 0.8.8.h, and it works fine. I've found the new version of Cacit pretty and simple, and i try to import my old plugins, like netMet, mactracks, Znets, GPSMap, Weathermap, and so one, by doing a recopy beetween my old server to the new one. But inside the menu "plugins", all of them are shown "incompatible". Is there a way to bypass, or all the plugins need to be rewritten ? Sincerly, Emmanuel ------------------------------------------ Emmanuel REUTER IFSTTAR - Systèmes d'Informations et Ressources Informatiques Site de Bron Cité des mobilités 25 avenue François Mitterrand 69675 Bron Cedex Tél. : (+33) 04.72.14.25.54 ------------------------------------------ "Personne n'est devenu fort en montrant comment une autre personne est faible". (Nelson Mandela) |
|
From: Tony R. <tr...@ca...> - 2017-03-20 04:08:21
|
*** Release of Cacti 1.1.0 *** Special thanks to all that have helped by contributing code and reporting issues on GitHub! We would not be where we are today without the help. Let's continue to grow the Cacti community! We do consider this to be the most stable 1.0.0 release yet! If you encounter any issues please visit the forums or submit an issue on GitHub. For additional details check out the README located on GitHub. https://github.com/Cacti/cacti/blob/develop/README.md *** Contribute *** Active development of Cacti is located on GitHub! Join us in making Cacti better, submit issues, fork and submit pull requests! https://github.com/cacti/ *** Cacti Change Log *** issue#337: Generic SNMP OID Graph Template damanged issue#338: Extremely slow new graph/DS creation issue#353: Broadcast & Multicast Packet counters missing issue#376: Structured RRD path permission issues issue#389: Manual template based graph creation not working issue#407: The RRDfile does not exist message is misleading issue#410: Select character data was interpreted as hex by cacti_snmp_walk() issue#422: additional issues with LDAP authentication issue#424: Automation does not discover devices w/o resolvable hostnames issue#427: undefined index TotalVisibleMemorySize on FreeBSD issue#432: SpikeKill menu wonky on Paw Theme issue#434: password_verify not compatible in php5.4- issue#435: urlPath missing from paw theme links issue#436: Restricted user does not see graphs in tree view issue#443: Allow remote_agent.php through a NAT issue#446: No local admin when using multiple LDAP configuration issue#447: Creating another non data query graph from same template reuses first data source issue#449: exec_poll_php does not flush pipes when using script server issue#450: Graph list view - No Graphs Found issue: Improve email test exception errors and change default timeout to 10 seconds issue: When on links page, breadcrumbs would become corrupted issue: When upgrading from any version of Cacti to 1.0.5, SQL's relative to poller_reindex might appear issue: Color page performance poor issue: The Device dropdown on the Graph View page was unreliable issue: Aggregate and non-Device Graphs in list view had not Device or Title description issue: Re-engineer back button design to accomocate ajax and native navigation issue: Make Graph Template filter wider issue: Resolve some visual issues in Classic theme feature: Add page refresh API to make page refreshing in Ajax easier to accomplish feature: Update fontawesome to version 4.7 feature: Use fontawesome glyphs for menu items feature: Support multiple column sort in table library feature: Add glyphs to main Cacti console menu *** Reporting Issues *** http://www.cacti.net/issues.php *** Download Cacti *** http://www.cacti.net/download_cacti.php *** Download Spine *** http://www.cacti.net/spine_download.php Thanks! The Cacti Group |
|
From: <jer...@or...> - 2017-03-15 08:48:37
|
Hello,
I have to present a vulnerability : CVE-2016-3172 (SQL Injection
/ tree.php) + CVE-2015-8604 (SQL Injection / graphs_new.php) in a university
defense
I installed cacti 0.8.8f on a virtual machine and i would replay the sql
injection.
Unfortunately I can not.
Could you help me ? How to replay this injection?
Thanks for your help
De : David Liedke [mailto:li...@rz...]
Envoyé : mercredi 15 mars 2017 08:10
À : STRABACH Jérôme DTSI/DERS
Objet : Re: Info CVE-2016-3172 (SQL Injection / tree.php) + CVE-2015-8604
(SQL Injection / graphs_new.php)
Hello,
Sorry - i dont know. I am only one of the package maintainers of the cacti
package in the openSUSE Repository.
Maybe you can ask on the "cacti-user" mailing list -->
http://cacti.net/mailing_lists.php
Good luck.
Regards,
David
Am 14.03.2017 um 19:01 schrieb jer...@or...:
Hello,
I am a student at the University of Lille, in France
I begin my studies in network security.
I have to present a vulnerability : CVE-2016-3172 (SQL Injection / tree.php)
+ CVE-2015-8604 (SQL Injection / graphs_new.php)
For CVE-2015-8604 :
http://www.cvedetails.com/cve-details.php?t=1
<http://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-2015-8604>
&cve_id=CVE-2015-8604
http://www.openwall.com/lists/oss-security/2016/03/10/13
CVE-2016-3172
https://www.cvedetails.com/cve-details.php?t=1
<https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-2016-3172>
&cve_id=CVE-2016-3172
I installed cacti 0.8.8f on a virtual machine and i would replay the sql
injection.
Unfortunately I can not.
Could you help me ? How to replay this injection?
Thanks for your help
|
|
From: Tony R. <tr...@ca...> - 2017-03-15 02:22:56
|
*** Release of Cacti 1.0.6 ***
We the Cacti Group are proud to release the following:
Cacti 1.0.6
Spine 1.0.6
For additional details check out the README located on GitHub.
https://github.com/Cacti/cacti/blob/develop/README.md
*** Contribute ***
Active development of Cacti is located on GitHub! Join us in making
Cacti better, submit issues, fork and submit pull requests!
https://github.com/cacti/
*** Cacti Change Log ***
issue#386: Allow special characters in graph title
issue#414: Install Wizard check path for spine
issue#415: SNMP session handling broken
issue#418: LDAP create user from template not working
*** Reporting Issues ***
http://www.cacti.net/issues.php
*** Download Cacti ***
http://www.cacti.net/download_cacti.php
*** Download Spine ***
http://www.cacti.net/spine_download.php
Thanks!
The Cacti Group
|
|
From: Eric G. <ekg...@se...> - 2017-03-14 16:02:54
|
Fixed it. Many thanks EKG > On Mar 14, 2017, at 10:28 AM, David Liedke <li...@rz...> wrote: > > https://github.com/Cacti/cacti/issues/415 > > Am 14.03.2017 um 15:04 schrieb Eric Germann: >> I just upgraded from 1.04 to 1.05. Nothing else changed. I now receive >> >> PCOMMAND Device[264] WARNING: Recache Event Detected for Device for every single host polled via ucd/net snmp. >> >> Any ideas where to look? >> >> Running poller.php returns values just fine. >> >> Setting to debug level yields hundreds of. >> >> 2017-03-14 06:40:00 - POLLER: Poller[1] ASSERT: '2=U' failed. Recaching host '172.28.10.12', data query #1 >> 2017-03-14 06:40:00 - POLLER: Poller[1] ASSERT: '2=U' failed. Recaching host '172.28.10.12', data query #2 >> >> The number before the = may vary, but same messages. >> >> Graphs have no data since now. >> >> Trying to figure out how to roll back > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot_______________________________________________ > cacti-user mailing list > cac...@li... > https://lists.sourceforge.net/lists/listinfo/cacti-user |
|
From: David L. <li...@rz...> - 2017-03-14 14:44:05
|
https://github.com/Cacti/cacti/issues/415 Am 14.03.2017 um 15:04 schrieb Eric Germann: > I just upgraded from 1.04 to 1.05. Nothing else changed. I now receive > > PCOMMAND Device[264] WARNING: Recache Event Detected for Device for every single host polled via ucd/net snmp. > > Any ideas where to look? > > Running poller.php returns values just fine. > > Setting to debug level yields hundreds of. > > 2017-03-14 06:40:00 - POLLER: Poller[1] ASSERT: '2=U' failed. Recaching host '172.28.10.12', data query #1 > 2017-03-14 06:40:00 - POLLER: Poller[1] ASSERT: '2=U' failed. Recaching host '172.28.10.12', data query #2 > > The number before the = may vary, but same messages. > > Graphs have no data since now. > > Trying to figure out how to roll back |
|
From: Eric G. <ekg...@se...> - 2017-03-14 14:21:33
|
I just upgraded from 1.04 to 1.05. Nothing else changed. I now receive PCOMMAND Device[264] WARNING: Recache Event Detected for Device for every single host polled via ucd/net snmp. Any ideas where to look? Running poller.php returns values just fine. Setting to debug level yields hundreds of. 2017-03-14 06:40:00 - POLLER: Poller[1] ASSERT: '2=U' failed. Recaching host '172.28.10.12', data query #1 2017-03-14 06:40:00 - POLLER: Poller[1] ASSERT: '2=U' failed. Recaching host '172.28.10.12', data query #2 The number before the = may vary, but same messages. Graphs have no data since now. Trying to figure out how to roll back |
|
From: Mik J <mik...@ya...> - 2017-03-14 00:58:52
|
T'es pas très curieux pour quelqu'un qui fait de la sécurité.Tu demandes les réponses sans être allé au bout des choses, certes tu as un peu cherché et bien formulé ton mail mais c'est vraiment pas assez...vraiment pas.
Trouve le code avant correctif et après correctif, fais un diff. Tu observeras ce qui a été corrigé et ça sera un bon début pour trouver comment reproduire l'exploit.
Et prépare toi à recevoir du spam puisque tu as écris avec ta boite pro =))
Le Mercredi 8 mars 2017 11h38, "jer...@or..." <jer...@or...> a écrit :
Hello,
I am a student at the University of Lille, in France
I begin my studies in network security.
I have to present a vulnerability : CVE-2016-3172 (SQL Injection / tree.php) + CVE-2015-8604 (SQL Injection / graphs_new.php)
For CVE-2015-8604 :
http://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-2015-8604
http://www.openwall.com/lists/oss-security/2016/03/10/13
Can you explain this vulnerability :
- how to reproduce it ?
- how to correct it?
"The parameter parent_id is used without any validation."
- Can you explain what the "parent_id" is, what is its function?
- What is the impact ? An example ?
I don't have access to cacti bug tracker :
- Can you give me a copy of the cacti bug tracker :
- Can you tell me, how this CVE was corrected ? The simple principle ?
the same thing for CVE-2016-3172
https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-2016-3172
thank you
Cordialement
[Logo Orange]<http://www.orange.com/>
Jérôme Strabach
Analyste Qualité de fonctionnement du Réseaux Cœur Voix
ORANGE/OF/DTSI/DERS/DR/DRM/VMI/CCI ET PERF
Lyon Sévigné
Mobile : +33 6 71 54 75 23 <https://monsi.sso.francetelecom.fr/index.asp?target=http%3A%2F%2Fclicvoice.sso.francetelecom.fr%2FClicvoiceV2%2FToolBar.do%3Faction%3Ddefault%26rootservice%3DSIGNATURE%26to%3D+33%206%2071%2054%2075%2023>
jer...@or...<mailto:jer...@or...>
[cid:image002.png@01D297FD.49A313F0]
_________________________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.
------------------------------------------------------------------------------
Announcing the Oxford Dictionaries API! The API offers world-renowned
dictionary content that is easy and intuitive to access. Sign up for an
account today to start using our lexical data to power your apps and
projects. Get started today and enter our developer competition.
http://sdm.link/oxford
_______________________________________________
cacti-user mailing list
cac...@li...
https://lists.sourceforge.net/lists/listinfo/cacti-user
|
|
From: Tony R. <tr...@ca...> - 2017-03-13 03:54:39
|
*** Release of Cacti 1.0.5 ***
We the Cacti Group are proud to release the following:
Cacti 1.0.5
Spine 1.0.5
For additional details check out the README located on GitHub.
https://github.com/Cacti/cacti/blob/develop/README.md
*** Contribute ***
Active development of Cacti is located on GitHub! Join us in making
Cacti better, submit issues, fork and submit pull requests!
https://github.com/cacti/
*** Cacti Change Log ***
issue#296: Poller warning for Non-SNMP device
issue#319: Add default 'High Collection Rate' data source profile
to new installs to demonstrate concept of multiple rates
issue#330: Import templates to non-default Data Profile
issue#337: Error when try create new graph - SNMP - Generic OID
issue#342: Infinite loop in poller_automation.php with invalid
schedule
issue#343: Device discovery cannot handle dots in device name
issue#344: Unable to upgrade to latest Cacti on FreeBSD
issue#353: Legacy broadcast & multicast packet counters missing in
interface.xml
issue#354: Place on tree dashes / ordering is not correct
issue#355: Replace table rows with count when using InnoDB tables
issue#357: If recovery mode runs longer than a polling interval, a
second is spawned
issue#358: Sending test e-mail results in warning
issue#360: Issue importing cacti.sql with some charsets
issue#364: Moving graph item causes page render issue
issue#365: ss_host_disk.php and ss_host_cpu.php should use return
issue#367: Upgrade chart.js to version 2.5
issue#368: Issue with device automation ip vs. ip_address
issue#369: Interface bits/second total Bandwidth wrong CDEF
issue#375: Drag and Drop of Devices and Graphs allows dropping
onto self
issue#380: Ignores a non-standard SNMP port
issue#382: When using php5.5+ new users unable to change their
password
issue#384: graph_view.php backtrace errors
issue#385: Unable to place an aggregate grapn on a subtree
issue#390: Display graphs from this aggregate icon next to graph not
displaying
issue#392: cdef.php missing sql where for system cdef's
issue#398: checkbox is not honored when creating tree
issue#399: External link configuration: Order buttons don't work
issue#400: SNMP Engine ID (v3) field too short
issue#401: Graphs -> Apply Automation Rules fails
issue#404: Success even when test mail fails
issue#406: HRULE text format special characters not escaped
issue#408: Suppress SNMP units suffix from cacti_snmp_get() output
issue: Improve is_ipaddress functions
issue: Drag & drop showing when disabled on page
automation_templates.php
issue: Output messages displayed incorrectly in
automation_templates.php and automation_snmp.php
issue: Importing template from old Cacti would not show data templates
issue: Handle snmp error exceptions better
issue: Update Apache .htaccess files to support multiple version
issue: When executing a full sync, if the table structured has
changed, recreate the remote table
issue: Multiple domains not working as expected
feature#197: Add external_id to Cacti for linking Cacti to other
monitoring systems
feature#332: Support copy user groups
feature: Log proper IP address if logging in behind a NAT
feature: New qquery parsing rules: VALUE/TEST, VALUE/TABLE,
VALUE/HEX2IP
*** Reporting Issues ***
http://www.cacti.net/issues.php
*** Download Cacti ***
http://www.cacti.net/download_cacti.php
*** Download Spine ***
http://www.cacti.net/spine_download.php
Thanks!
The Cacti Group
|
|
From: Wolfgang B. <wba...@gb...> - 2017-03-08 18:54:44
|
> Hi, > > I did an upgrade from 0.8.8g to 1.0.4 and it went quite well, I can login > to the web interface, graphs are updating, but I can't make any changes > through the web interface. > > For example if I go to Settings, and try to change the path for the cacti > log, hit "Save" and the page reloads with the old path still showing. > > Same happens if I try to delete a device under "Devices". I select delete > under "Choose an action" and the page reloads with the selected devices > not deleted. > > OS RHEL6 > PHP version 5.6.30 > MySQL version 5.1.73 > Apache 2.2.31 > > Any ideas what might be wrong? The database user can definitely write to > the db and I don't get any errors in any logs. Any help appreciated. > > Wolfgang > > It turn's out my Apache configuration was responsible for this behaviour. I had a redirect in there that was confusing the cacti URLs. Sorry for the noise. Wolfgang |
|
From: Jarosław K. - I. <jk...@in...> - 2017-03-08 12:46:57
|
This version is obsolette use gitversion. Please make an issue on github: https://github.com/Cacti/cacti Regards JK On 08.03.2017 11:37, jer...@or... wrote: > Hello, > > I am a student at the University of Lille, in France > I begin my studies in network security. > I have to present a vulnerability : CVE-2016-3172 (SQL Injection / tree.php) + CVE-2015-8604 (SQL Injection / graphs_new.php) > > For CVE-2015-8604 : > http://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-2015-8604 > http://www.openwall.com/lists/oss-security/2016/03/10/13 > > Can you explain this vulnerability : > - how to reproduce it ? > - how to correct it? > "The parameter parent_id is used without any validation." > > - Can you explain what the "parent_id" is, what is its function? > > - What is the impact ? An example ? > > > > I don't have access to cacti bug tracker : > > - Can you give me a copy of the cacti bug tracker : > > - Can you tell me, how this CVE was corrected ? The simple principle ? > > > > the same thing for CVE-2016-3172 > > https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-2016-3172 > > thank you > > Cordialement > > [Logo Orange]<http://www.orange.com/> > Jérôme Strabach > Analyste Qualité de fonctionnement du Réseaux Cœur Voix > ORANGE/OF/DTSI/DERS/DR/DRM/VMI/CCI ET PERF > Lyon Sévigné > Mobile : +33 6 71 54 75 23 <https://monsi.sso.francetelecom.fr/index.asp?target=http%3A%2F%2Fclicvoice.sso.francetelecom.fr%2FClicvoiceV2%2FToolBar.do%3Faction%3Ddefault%26rootservice%3DSIGNATURE%26to%3D+33%206%2071%2054%2075%2023> > jer...@or...<mailto:jer...@or...> > > [cid:image002.png@01D297FD.49A313F0] > > > _________________________________________________________________________________________________________________________ > > Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc > pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler > a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, > Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. > > This message and its attachments may contain confidential or privileged information that may be protected by law; > they should not be distributed, used or copied without authorisation. > If you have received this email in error, please notify the sender and delete this message and its attachments. > As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. > Thank you. > > > > > ------------------------------------------------------------------------------ > Announcing the Oxford Dictionaries API! The API offers world-renowned > dictionary content that is easy and intuitive to access. Sign up for an > account today to start using our lexical data to power your apps and > projects. Get started today and enter our developer competition. > http://sdm.link/oxford > > > _______________________________________________ > cacti-user mailing list > cac...@li... > https://lists.sourceforge.net/lists/listinfo/cacti-user -- Jarosław Kłopotek kom. 607 893 111 Interduo Ł. Bujek, J. Kłopotek, J. Sowa s.c. ul. Lubelska 36B/40, 21-100 Lubartów tel. 81 475 30 00 |
|
From: <jer...@or...> - 2017-03-08 10:37:11
|
Hello, I am a student at the University of Lille, in France I begin my studies in network security. I have to present a vulnerability : CVE-2016-3172 (SQL Injection / tree.php) + CVE-2015-8604 (SQL Injection / graphs_new.php) For CVE-2015-8604 : http://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-2015-8604 http://www.openwall.com/lists/oss-security/2016/03/10/13 Can you explain this vulnerability : - how to reproduce it ? - how to correct it? "The parameter parent_id is used without any validation." - Can you explain what the "parent_id" is, what is its function? - What is the impact ? An example ? I don't have access to cacti bug tracker : - Can you give me a copy of the cacti bug tracker : - Can you tell me, how this CVE was corrected ? The simple principle ? the same thing for CVE-2016-3172 https://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-2016-3172 thank you Cordialement [Logo Orange]<http://www.orange.com/> Jérôme Strabach Analyste Qualité de fonctionnement du Réseaux Cœur Voix ORANGE/OF/DTSI/DERS/DR/DRM/VMI/CCI ET PERF Lyon Sévigné Mobile : +33 6 71 54 75 23 <https://monsi.sso.francetelecom.fr/index.asp?target=http%3A%2F%2Fclicvoice.sso.francetelecom.fr%2FClicvoiceV2%2FToolBar.do%3Faction%3Ddefault%26rootservice%3DSIGNATURE%26to%3D+33%206%2071%2054%2075%2023> jer...@or...<mailto:jer...@or...> [cid:image002.png@01D297FD.49A313F0] _________________________________________________________________________________________________________________________ Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation. If you have received this email in error, please notify the sender and delete this message and its attachments. As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. Thank you. |
|
From: Wolfgang B. <wba...@gb...> - 2017-03-07 00:42:17
|
Hi, I did an upgrade from 0.8.8g to 1.0.4 and it went quite well, I can login to the web interface, graphs are updating, but I can't make any changes through the web interface. For example if I go to Settings, and try to change the path for the cacti log, hit "Save" and the page reloads with the old path still showing. Same happens if I try to delete a device under "Devices". I select delete under "Choose an action" and the page reloads with the selected devices not deleted. OS RHEL6 PHP version 5.6.30 MySQL version 5.1.73 Apache 2.2.31 Any ideas what might be wrong? The database user can definitely write to the db and I don't get any errors in any logs. Any help appreciated. Wolfgang |
|
From: Jarosław K. - I. <jk...@in...> - 2017-03-03 22:46:38
|
Please update to git version. The problem not exists. On 03.03.2017 18:20, Danny Cox wrote: > After moving the thold plugin into the plugins folder, I am no longer able to see any plugins. > > If I remove it, I am then able to manage all previously installed plugins. > > Version 0.8.8h on Windows 2012 server. > > Thanks, > > Danny H. Cox > Infrastructure Manager > Off: (408) 514 6549 > Cell: (408) 313-3937 > dan...@vi...<mailto:dan...@vi...> > [cid:image001.jpg@01CDD917.A2599EF0] > www.viewglass.com<http://www.viewglass.com/> > > > > > This message and any attachments may contain confidential information of View, Inc. If you are not the intended recipient you are hereby notified that any dissemination, copying or distribution of this message, or files associated with this message, is strictly prohibited. If you have received this message in error, please notify us immediately by replying to the message and delete the message from your computer. > > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > _______________________________________________ > cacti-user mailing list > cac...@li... > https://lists.sourceforge.net/lists/listinfo/cacti-user -- Jarosław Kłopotek kom. 607 893 111 Interduo Ł. Bujek, J. Kłopotek, J. Sowa s.c. ul. Lubelska 36B/40, 21-100 Lubartów tel. 81 475 30 00 |
|
From: Danny C. <dan...@vi...> - 2017-03-03 17:21:02
|
After moving the thold plugin into the plugins folder, I am no longer able to see any plugins. If I remove it, I am then able to manage all previously installed plugins. Version 0.8.8h on Windows 2012 server. Thanks, Danny H. Cox Infrastructure Manager Off: (408) 514 6549 Cell: (408) 313-3937 dan...@vi...<mailto:dan...@vi...> [cid:image001.jpg@01CDD917.A2599EF0] www.viewglass.com<http://www.viewglass.com/> This message and any attachments may contain confidential information of View, Inc. If you are not the intended recipient you are hereby notified that any dissemination, copying or distribution of this message, or files associated with this message, is strictly prohibited. If you have received this message in error, please notify us immediately by replying to the message and delete the message from your computer. |