Title : Debian Security Update Fixes Cacti "cmd.php" Remote Code Injection Vulnerability VUPEN ID : VUPEN/ADV-2007-0224 CVE ID : CVE-2006-6799
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-18
Technical Description
Debian has released security updates to address a vulnerability identified in Cacti. This issue could be exploited by attackers to execute arbitrary commands. For additional information, see : VUPEN/ADV-2006-5193
Debian GNU/Linux stable (sarge) - Upgrade to version 0.8.6c-7sarge4
Debian GNU/Linux unstable (sid) - Upgrade to version 0.8.6i-3
Debian GNU/Linux testing (etch) - Upgrade to version 0.8.6i-3 References