Skip to content

Rubioo02/CVE-2024-29895

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

CVE-2024-29895 - RCE ON CACTI

Warning

This is an educational project, I am not responsible for any use

Usage:

python3 poc.py -c whoami [-u https://localhost] [-f urls.txt]

CVE-2024-29895

CVE-2024-29895, Is a command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server

How does it work?

On cacti versions 1.3.X dev where cmd_realtime.php is present and register_argc_argv option is ON the command injection is possible thanks to manipulation of the poller_id parameter of an input in a get request

Dork:

Google: inurl:cmd_realtime.php

Shodan: Cacti

About

CVE-2024-29895 | RCE on CACTI 1.3.X dev

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages