跳转到帖子

Cacti RCE via SQLi in pollers.php

recommended_posts

发布于
  • Members

Cacti RCE via SQLi in pollers.php

Disclosed
12/20/2023
Created
02/02/2024

Description

This exploit module leverages a SQLi (CVE-2023-49085) and a LFI (CVE-2023-49084) vulnerability in Cacti versions prior to 1.2.26 to achieve RCE. Authentication is needed and the account must have access to the vulnerable PHP script (`pollers.php`). This is granted by setting the `Sites/Devices/Data` permission in the `General Administration` section.

Author(s)

  • Aleksey Solovev
  • Christophe De La Fuente

Platform

Windows

Architectures

cmd

Development

  • Source Code
  • History
  • 查看数 706
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…