Debian Security Advisory DSA 3007-1 (cacti - security update)

Summary
Multiple security issues (cross-site scripting, missing input sanitising and SQL injection) have been discovered in Cacti, a web interface for graphing of monitoring systems.
Solution
For the stable distribution (wheezy), these problems have been fixed in version 0.8.8a+dfsg-5+deb7u4. For the unstable distribution (sid), these problems have been fixed in version 0.8.8b+dfsg-8. We recommend that you upgrade your cacti packages.
Insight
Cacti is a complete PHP-driven front-end for RRDTool. It stores all of the necessary data source information to create graphs, handles the data gathering, and populates the MySQL database with round-robin archives. It also includes SNMP support for those used to creating traffic graphs with MRTG.
Affected
cacti on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References