e04c03
------------------------------------------------------------------------
e04c03
r7439 | rony | 2014-03-30 17:52:10 -0500 (Sun, 30 Mar 2014) | 5 lines
e04c03
e04c03
bug#0002405: SQL injection in graph_xport.php
e04c03
e04c03
 - Fixed form input validation problems
e04c03
 - Fixed rrd export and graph shell escape issues
e04c03
e04c03
------------------------------------------------------------------------
e04c03
Index: branches/0.8.8/graph_xport.php
e04c03
===================================================================
e04c03
--- branches/0.8.8/graph_xport.php	(revision 7438)
e04c03
+++ branches/0.8.8/graph_xport.php	(revision 7439)
e04c03
@@ -47,43 +47,48 @@
e04c03
 
e04c03
 $graph_data_array = array();
e04c03
 
e04c03
+/* ================= input validation ================= */
e04c03
+input_validate_input_number(get_request_var("local_graph_id"));
e04c03
+input_validate_input_number(get_request_var("rra_id"));
e04c03
+/* ==================================================== */
e04c03
+
e04c03
 /* override: graph start time (unix time) */
e04c03
-if (!empty($_GET["graph_start"]) && $_GET["graph_start"] < 1600000000) {
e04c03
-	$graph_data_array["graph_start"] = $_GET["graph_start"];
e04c03
+if (!empty($_GET["graph_start"]) && is_numeric($_GET["graph_start"] && $_GET["graph_start"] < 1600000000)) {
e04c03
+	$graph_data_array["graph_start"] = get_request_var("graph_start");
e04c03
 }
e04c03
 
e04c03
 /* override: graph end time (unix time) */
e04c03
-if (!empty($_GET["graph_end"]) && $_GET["graph_end"] < 1600000000) {
e04c03
-	$graph_data_array["graph_end"] = $_GET["graph_end"];
e04c03
+if (!empty($_GET["graph_end"]) && is_numeric($_GET["graph_end"]) && $_GET["graph_end"] < 1600000000) {
e04c03
+	$graph_data_array["graph_end"] = get_request_var("graph_end");
e04c03
 }
e04c03
 
e04c03
 /* override: graph height (in pixels) */
e04c03
-if (!empty($_GET["graph_height"]) && $_GET["graph_height"] < 3000) {
e04c03
-	$graph_data_array["graph_height"] = $_GET["graph_height"];
e04c03
+if (!empty($_GET["graph_height"]) && is_numeric($_GET["graph_height"]) && $_GET["graph_height"] < 3000) {
e04c03
+	$graph_data_array["graph_height"] = get_request_var("graph_height");
e04c03
 }
e04c03
 
e04c03
 /* override: graph width (in pixels) */
e04c03
-if (!empty($_GET["graph_width"]) && $_GET["graph_width"] < 3000) {
e04c03
-	$graph_data_array["graph_width"] = $_GET["graph_width"];
e04c03
+if (!empty($_GET["graph_width"]) && is_numeric($_GET["graph_width"]) && $_GET["graph_width"] < 3000) {
e04c03
+	$graph_data_array["graph_width"] = get_request_var("graph_width");
e04c03
 }
e04c03
 
e04c03
 /* override: skip drawing the legend? */
e04c03
 if (!empty($_GET["graph_nolegend"])) {
e04c03
-	$graph_data_array["graph_nolegend"] = $_GET["graph_nolegend"];
e04c03
+	$graph_data_array["graph_nolegend"] = get_request_var("graph_nolegend");
e04c03
 }
e04c03
 
e04c03
 /* print RRDTool graph source? */
e04c03
 if (!empty($_GET["show_source"])) {
e04c03
-	$graph_data_array["print_source"] = $_GET["show_source"];
e04c03
+	$graph_data_array["print_source"] = get_request_var("show_source");
e04c03
 }
e04c03
 
e04c03
-$graph_info = db_fetch_row("SELECT * FROM graph_templates_graph WHERE local_graph_id='" . $_REQUEST["local_graph_id"] . "'");
e04c03
+$graph_info = db_fetch_row("SELECT * FROM graph_templates_graph WHERE local_graph_id='" . get_request_var("local_graph_id") . "'");
e04c03
 
e04c03
 /* for bandwidth, NThPercentile */
e04c03
 $xport_meta = array();
e04c03
 
e04c03
 /* Get graph export */
e04c03
-$xport_array = @rrdtool_function_xport($_GET["local_graph_id"], $_GET["rra_id"], $graph_data_array, $xport_meta);
e04c03
+$xport_array = @rrdtool_function_xport($_GET["local_graph_id"], get_request_var("rra_id"), $graph_data_array, $xport_meta);
e04c03
 
e04c03
 /* Make graph title the suggested file name */
e04c03
 if (is_array($xport_array["meta"])) {
e04c03
Index: branches/0.8.8/lib/rrd.php
e04c03
===================================================================
e04c03
--- branches/0.8.8/lib/rrd.php	(revision 7438)
e04c03
+++ branches/0.8.8/lib/rrd.php	(revision 7439)
e04c03
@@ -865,13 +865,13 @@
e04c03
 	/* basic graph options */
e04c03
 	$graph_opts .=
e04c03
 		"--imgformat=" . $image_types{$graph["image_format_id"]} . RRD_NL .
e04c03
-		"--start=$graph_start" . RRD_NL .
e04c03
-		"--end=$graph_end" . RRD_NL .
e04c03
+		"--start=" . cacti_escapeshellarg($graph_start) . RRD_NL .
e04c03
+		"--end=" . cacti_escapeshellarg($graph_end) . RRD_NL .
e04c03
 		"--title=" . cacti_escapeshellarg($graph["title_cache"]) . RRD_NL .
e04c03
 		"$rigid" .
e04c03
-		"--base=" . $graph["base_value"] . RRD_NL .
e04c03
-		"--height=$graph_height" . RRD_NL .
e04c03
-		"--width=$graph_width" . RRD_NL .
e04c03
+		"--base=" . cacti_escapeshellarg($graph["base_value"]) . RRD_NL .
e04c03
+		"--height=" . cacti_escapeshellarg($graph_height) . RRD_NL .
e04c03
+		"--width=" . cacti_escapeshellarg($graph_width) . RRD_NL .
e04c03
 		"$scale" .
e04c03
 		"$unit_value" .
e04c03
 		"$unit_exponent_value" .
e04c03
@@ -1606,8 +1606,8 @@
e04c03
 
e04c03
 	/* basic export options */
e04c03
 	$xport_opts =
e04c03
-		"--start=$xport_start" . RRD_NL .
e04c03
-		"--end=$xport_end" . RRD_NL .
e04c03
+		"--start=" . cacti_escapeshellarg($xport_start) . RRD_NL .
e04c03
+		"--end=" . cacti_escapeshellarg($xport_end) . RRD_NL .
e04c03
 		"--maxrows=10000" . RRD_NL;
e04c03
 
e04c03
 	$xport_defs = "";
e04c03
@@ -1997,7 +1997,7 @@
e04c03
 			$stacked_columns["col" . $j] = ($graph_item_types{$xport_item["graph_type_id"]} == "STACK") ? 1 : 0;
e04c03
 			$j++;
e04c03
 
e04c03
-			$txt_xport_items .= "XPORT:" . $data_source_name . ":" . str_replace(":", "", cacti_escapeshellarg($legend_name)) ;
e04c03
+			$txt_xport_items .= "XPORT:" . cacti_escapeshellarg($data_source_name) . ":" . str_replace(":", "", cacti_escapeshellarg($legend_name)) ;
e04c03
 		}else{
e04c03
 			$need_rrd_nl = FALSE;
e04c03
 		}