Bug#479621: (no subject)

2008-05-06 Thread J.M.Roth
The following change, courtesy of the Ubuntu cacti-0.8.6i package, fixes the problem: /usr/share/cacti/include/config.php, line 86: change: if (!((is_file($_SERVER[SCRIPT_FILENAME])) (substr_count($_SERVER [SCRIPT_FILENAME], $_SERVER[PHP_SELF] { to: if

Bug#479621: (no subject)

2008-05-06 Thread sean finney
On Tuesday 06 May 2008 03:31:34 pm J.M.Roth wrote: Just make sure that if you fix the problem (again), that the fix is in the spirit of the actual Cacti security advisory. afaik it is. Currently, I am having a hard time seeing why exactly all these checks are done. Maybe someone could