Amazon Linux AMI : cacti Multiple Vulnerabilities (ALAS-2011-23)

This script is Copyright (C) 2013 Tenable Network Security, Inc.


Synopsis :

The remote Amazon Linux AMI host is missing a security update.

Description :

The release notes for Cacti 0.8.7h indicate that two security
vulnerabilities were fixed, though no corresponding CVE has been
issued.

SQL injection issue with user login.

Cross-site scripting issues.

See also :

http://www.cacti.net/release_notes_0_8_7h.php
https://admin.fedoraproject.org/updates/cacti-0.8.7h-1.el5
http://www.nessus.org/u?f4dd009a

Solution :

Run 'yum upgrade cacti' to upgrade your system.

Risk factor :

High

Family: Amazon Linux Local Security Checks

Nessus Plugin ID: 69582 ()

Bugtraq ID:

CVE ID: