Bugzilla – Bug 884326
VUL-0: CVE-2014-4002: cacti: Cross-Site Scripting Vulnerability
Last modified: 2015-06-11 09:51:41 UTC
Cacti upstream's svn http://svn.cacti.net/viewvc?view=rev&revision=7452 has a fix for CVE-2014-4002. No more technical information is available unfortunately. It might be that also the change before this revision is also involved http://svn.cacti.net/viewvc?view=rev&revision=7451 References: https://bugzilla.redhat.com/show_bug.cgi?id=1113035 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-4002 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4002
bugbot adjusting priority
Already fixed, openSUSE 13.1 and 13.2 are at 0.8.8c via version update.