Vulnerability Bulletins

DSA-3494 cacti - security update

   
Affected software Debian
 
Two SQL injection vulnerabilities were discovered in cacti, a webinterface for graphing of monitoring systems. Specially crafted inputcan be used by an attacker in parameters of the graphs_new.php script toexecute arbitrary SQL commands on the database.

More info:

https://www.debian.org/security/2016/dsa-3494