LWN.net Logo

cacti: multiple vulnerabilities

Package(s):cacti CVE #(s):CVE-2013-5588 CVE-2013-5589
Created:September 3, 2013 Updated:September 10, 2013
Description: From the CVE entries:

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the step parameter to install/index.php or (2) the id parameter to cacti/host.php. (CVE-2013-5588)

SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. (CVE-2013-5589)

Alerts:
Debian DSA-2747-1 2013-08-31
Fedora FEDORA-2013-15444 2013-09-06
Fedora FEDORA-2013-15466 2013-09-06
Mandriva MDVSA-2013:228 2013-09-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds