Skip to content

ticofookfook/CVE-2024-29895.py

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

Cacti RCE - CVE-2024-29895

Usage:

python3 cve-2024-29895.py -u https://target.com/ -c id

Affecting Cacti versions 1.3.X on DEV builds where cmd_realtime.php is present and POLLER_ID is enabled.

Command Injection is possible via this endpoint, by requesting via GET with payload as HTML Query Parameters

Dork:

Google: inurl:cmd_realtime.php

Shodan: Cacti

Hunter.how: /product.name="Cacti"

FOFA: app="Cacti-Monitoring"

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages