Index: vuln.xml =================================================================== --- vuln.xml (revision 392536) +++ vuln.xml (working copy) @@ -58,6 +58,50 @@ --> + + cacti -- Multiple XSS and SQL injection vulnerabilities + + + cacti + 0.8.8e + + + + +

The Cacti Group, Inc. reports:

+
+

Important Security Fixes

+
    +
  • Multiple XSS and SQL injection vulnerabilities
  • +
  • CVE-2015-4634 - SQL injection in graphs.php
  • +
+

Changelog

+
    +
  • bug: Fixed various SQL Injection vectors
  • +
  • bug#0002574: SQL Injection Vulnerabilities in graph items and + graph template items
  • +
  • bug#0002577: CVE-2015-4634 - SQL injection in graphs.php
  • +
  • bug#0002579: SQL Injection Vulnerabilities in data sources
  • +
  • bug#0002580: SQL Injection in cdef.php
  • +
  • bug#0002582: SQL Injection in data_templates.php
  • +
  • bug#0002583: SQL Injection in graph_templates.php
  • +
  • bug#0002584: SQL Injection in host_templates.php
  • +
+
+ +
+ + CVE-2015-4634 + ports/201702 + http://www.cacti.net/release_notes_0_8_8e.php + http://seclists.org/oss-sec/2015/q3/150 + + + 2015-07-12 + 2015-07-20 + +
+ php-phar -- multiple vulnerabilities