This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Title Updated cacti packages fix multiple vulnerabilities
Name MDVSA-2008:052 First vendor Publication 2008-02-27
Vendor Mandriva Last vendor Modification 2008-02-27
Severity (Vendor) N/A Revision N/A

A number of vulnerabilities were found in the Cacti program, including XSS vulnerabilities, SQL injection vulnerabilities, CRLF injection vulnerabilities, and information disclosure vulnerabilities.

This update provides Cacti 0.8.6k which corrects these issues.

CWE : Common Weakness Enumeration

% Id Name
25 % CWE-200 Information Exposure
25 % CWE-94 Failure to Control Generation of Code ('Code Injection')
25 % CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('SQL Injection') (CWE/SANS Top 25)
25 % CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25)

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:20240
Oval ID: oval:org.mitre.oval:def:20240
Title: DSA-1569-1 cacti - multiple vulnerabilities
Description: It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitising, leading to cross site scripting and SQL injection being possible.
Family: unix Class: patch
Reference(s): DSA-1569-1
Version: 5
Platform(s): Debian GNU/Linux 4.0
Product(s): cacti
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:7735
Oval ID: oval:org.mitre.oval:def:7735
Title: DSA-1569 cacti -- insufficient input sanitising
Description: It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitising, leading to cross site scripting and SQL injection being possible.
Family: unix Class: patch
Reference(s): DSA-1569
Version: 3
Platform(s): Debian GNU/Linux 4.0
Product(s): cacti
Definition Synopsis:

