CVE-2020-8813
Description
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
NVD
Severity: HIGH
CVE ID: CVE-2020-8813
CVSS Score: 8.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Proof Of Concept
Nuclei Templates for CVE-2020-8813
Refrence: Project Discovery GitHub
mhaskar
The official exploit for Cacti v1.2.8 Remote Code Execution CVE-2020-8813
Refrence: GitHub
0xm4ud
Refrence: GitHub
hexcowboy
Cacti v1.2.8 Unauthenticated Remote Code Execution
Refrence: GitHub
p0dalirius
CVE-2020-8813 - RCE through graph_realtime.php in Cacti 1.2.8
Refrence: GitHub
Content on GitHub
cocomelonc | watchers:20
vulnexipy
Vulnerabilities exploitation examples, python
Refrence: GitHub