Multiple security vulnerabilities such as cross site scripting and SQL injection have been discovered in Cacti versions below 0.8.7b and 0.8.6k.
4d5536e480473c05419a2d4a87325aeafd226002691c479b6b3acec58bf8dda8
Important Security Fixes for Cacti
Multiple security vulnerabilities have been discovered in Cacti's web interface:
* XSS vulnerabilities
* Path disclosure vulnerabilities
* SQL injection vulnerabilities
* HTTP response splitting vulnerabilities
All the above issues have been addressed in a new release of Cacti:
* 0.8.7b - http://www.cacti.net/downloads/cacti-0.8.7b.tar.gz
* 0.8.6k - http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz
Patches for the following versions are available at:
* 0.8.7a - http://www.cacti.net/download_patches.php?version=0.8.7a
* 0.8.6j - http://www.cacti.net/download_patches.php?version=0.8.6j