
CVE-2020-8813 - RCE a través de graph_realtime.php en Cacti 1.2.8
En Cacti 1.2.8, el script graph_realtime.php permite a atacantes remotos ejecutar comandos arbitrarios del sistema operativo inyectando metacaracteres de shell en una cookie, siempre que se le haya concedido al usuario invitado el privilegio de gráficos en tiempo real.
$ ./CVE-2020-8813.py -h
PoC of CVE-2020-8813 - RCE through graph_realtime.php in Cacti 1.2.8 - by Remi GASCOU (Podalirius)
usage: CVE-2020-8813.py [-h] -t TARGET [-v] [-u USERNAME] [-p PASSWORD] (-L | -c COMMAND) [-k]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
Target URL of the cacti
-v, --verbose Verbose mode. (default: False)
-u USERNAME, --username USERNAME
Username to connect to Cacti
-p PASSWORD, --password PASSWORD
Password to connect to Cacti
-L, --live Live mode. (default: False)
-c COMMAND, --command COMMAND
Execute a single command
-k, --insecure Allow insecure server connections when using SSL (default: False)
Las pull requests son bienvenidas. No dudes en abrir un issue si quieres añadir otras funcionalidades.