Bug#820521: cacti: CVE-2016-3659: SQL injection vulnerability in graph_view.php

2016-04-28 Thread Paul Gevers
Control: tags -1 help For the record of this bug. I have not been able to reproduce this on my Debian system, and upstream hasn't responded yet to the bug report. Any help in reproducing and providing a script to reproducing is welcome. The script from the upstream bug report does not reproduce

Bug#820521: cacti: CVE-2016-3659: SQL injection vulnerability in graph_view.php

2016-04-09 Thread Salvatore Bonaccorso
Source: cacti Version: 0.8.8g+ds1-1 Severity: important Tags: security upstream Forwarded: http://bugs.cacti.net/view.php?id=2673 Hi, the following vulnerability was published for cacti. AFAICT, there is not yet an upstream patch for this issue. CVE-2016-3659[0]: Cacti graph_view.php SQL