Source: cacti Version: 0.8.7b-2.1+lenny3, 0.8.6i-3.6 Severity: grave Tags: security
CVE Number: CVE-2010-1644 Descriptions: Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) description parameter to host.php, or (3) the host_id parameter to data_sources.php. References: http://www.vupen.com/english/advisories/2010/1203 http://www.cacti.net/release_notes_0_8_7f.php Upstream commit: http://svn.cacti.net/viewvc?view=rev&revision=5901 Debian: http://security-tracker.debian.org/tracker/CVE-2010-1644 I'll take care for this issue -- [ Mahyuddin Susanto ] - 4096R/90B36C5B
signature.asc
Description: OpenPGP digital signature