Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Debian: DSA-2750-1 Important: Joomla! Remote Code Execution & XSS

debian
Calendar Grey August 31, 2013
Debian Logo
The recent update for Cacti focuses on mitigating risks related to remote access, cross-site scripting, and SQL injection threats within the Debian environment.
Two vulnerabilities were discovered in Cacti, a web interface for graphing of monitoring systems: CVE-2013-5588

Summary

Two vulnerabilities were discovered in Cacti, a web interface for
graphing of monitoring systems:

CVE-2013-5588

install/index.php and cacti/host.php suffered from Cross-Site
Scripting vulnerabilities.

CVE-2013-5589

cacti/host.php contained an SQL injection vulnerability, allowing
an attacker to execute SQL code on the database used by Cacti.

For the oldstable distribution (squeeze), these problems have been fixed in
version 0.8.7g-1+squeeze3.

For the stable distribution (wheezy), these problems have been fixed in
version 0.8.8a+dfsg-5+deb7u2.

For the unstable distribution (sid), these problems have been fixed in
version 0.8.8b+dfsg-3.

We recommend that you upgrade your cacti packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: cacti
CVE ID: CVE-2013-5588 CVE-2013-5589

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here