Skip to main content

CVE-2020-8813

Description

graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.

NVD
Severity: HIGH
CVE ID: CVE-2020-8813
CVSS Score: 8.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Refrence: NVDMITRE

Proof Of Concept

Nuclei Templates for CVE-2020-8813
mhaskar

The official exploit for Cacti v1.2.8 Remote Code Execution CVE-2020-8813

Refrence: GitHub

0xm4ud

Refrence: GitHub

hexcowboy

Cacti v1.2.8 Unauthenticated Remote Code Execution

Refrence: GitHub

p0dalirius

CVE-2020-8813 - RCE through graph_realtime.php in Cacti 1.2.8

Refrence: GitHub

Content on GitHub

cocomelonc | watchers:20

vulnexipy
Vulnerabilities exploitation examples, python

Refrence: GitHub