Amazon Linux AMI : cacti (ALAS-2016-711)

Medium Nessus Plugin ID 91470

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter. (CVE-2016-3659)

Solution

Run 'yum update cacti' to update your system.

See Also

https://alas.aws.amazon.com/ALAS-2016-711.html

Plugin Details

Severity: Medium

ID: 91470

File Name: ala_ALAS-2016-711.nasl

Version: 2.3

Type: local

Agent: unix

Published: 2016/06/06

Updated: 2018/04/18

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:cacti, cpe:/o:amazon:linux

Patch Publication Date: 2016/06/02

Reference Information

CVE: CVE-2016-3659

ALAS: 2016-711