vendor:
Cacti
by:
rgod
9
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Cacti
Affected Version From: 0.8.6i
Affected Version To: 0.8.6i
Patch Exists: YES
Related CWE: CVE-2008-4609
CPE: a:cacti:cacti
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows
2008
Cacti <= 0.8.6i "cmd.php" popen() injection
A vulnerability in Cacti <= 0.8.6i allows an attacker to execute arbitrary commands on the vulnerable system. This is due to the lack of proper input validation in the "cmd.php" script, which allows an attacker to inject arbitrary commands into the "popen()" function. This can be exploited to execute arbitrary commands with the privileges of the web server.
Mitigation:
Upgrade to the latest version of Cacti.