
PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22
Ce dépôt contient une preuve de concept (PoC) pour CVE-2022-46169 - RCE non authentifié sur Cacti <= 1.2.22 en enchaînant un contournement d'authentification et une injection de commande, décrit par Sonar dans cet article de blog. Les mêmes vulnérabilités ont également été découvertes par : Steven Seeley (mr_me) de Source Incite.
positional arguments:
target URL of the Cacti application.
optional arguments:
-f FILE File containing the command
-c CMD Command
--n_host_ids The range of host_ids to try (0 - n)
--n_local_data_ids The range of local_data_ids to try (0 - n)
