Bugzilla – Bug 935199
VUL-0: CVE-2015-2665: cacti: Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remoteattackers to inject ar...
Last modified: 2015-06-18 09:05:35 UTC
CVE-2015-2665 Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-2665 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2665 http://www.cacti.net/release_notes_0_8_8d.php http://www.fortiguard.com/advisory/FG-VD-15-017/
CVE-2015-4454 is also fixed by 0.8.8d SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
the 0.8.8d cacti update is tracked in bug 934187 *** This bug has been marked as a duplicate of bug 934187 ***