
CVE-2022-46169용 PoC - Cacti <= 1.2.22에서의 인증되지 않은 RCE
이 저장소에는 CVE-2022-46169에 대한 개념 증명(PoC)이 포함되어 있습니다. 이 취약점은 인증 우회와 명령 주입을 연쇄적으로 사용하여 Cacti <= 1.2.22에서 인증되지 않은 원격 코드 실행(RCE)을 가능하게 하며, Sonar의 블로그 게시물에 설명되어 있습니다. 동일한 취약점은 Source Incite의 Steven Seeley(mr_me)에 의해서도 발견되었습니다.
positional arguments:
target URL of the Cacti application.
optional arguments:
-f FILE File containing the command
-c CMD Command
--n_host_ids The range of host_ids to try (0 - n)
--n_local_data_ids The range of local_data_ids to try (0 - n)
