[CVE-2007-6035] cacti has a sql injection vulnerability
Bug #164072 reported by
Stephan Rügamer
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
cacti (Debian) |
Fix Released
|
Unknown
|
|||
cacti (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Dapper |
Fix Released
|
High
|
Brian Thomason | ||
Edgy |
Fix Released
|
High
|
Stephan Rügamer | ||
Feisty |
Fix Released
|
High
|
Stephan Rügamer | ||
Gutsy |
Fix Released
|
High
|
Stephan Rügamer | ||
Hardy |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: cacti
Dear Colleagues,
a sql injection vulnerability was found for cacti < 0.8.7a.
From NVD:
SQL injection vulnerability in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Regards,
\sh
Changed in cacti: | |
status: | Unknown → Fix Released |
Changed in cacti: | |
status: | Fix Committed → Fix Released |
status: | Fix Committed → Fix Released |
status: | Fix Committed → Fix Released |
Changed in cacti: | |
assignee: | shermann → brian-thomason |
To post a comment you must log in.
I believe that CVE-2007-311[23] also affect all releases. It might be good to fix those now too.