|
|
| |
|
| |
cacti: multiple vulnerabilities
| Package(s): | cacti |
CVE #(s): | CVE-2013-5588
CVE-2013-5589
|
| Created: | September 3, 2013 |
Updated: | September 10, 2013 |
| Description: |
From the CVE entries:
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the step parameter to install/index.php or (2) the id parameter to cacti/host.php. (CVE-2013-5588)
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. (CVE-2013-5589) |
| Alerts: |
|
( Log in to post comments)
|
|
|