Sploitus

Exploit for Incorrect Authorization in Cacti

githubexploit Β· 2023-08-30

Exploit Code

README18 lines
## https://sploitus.com/exploit?id=8CF655BA-C516-5C6F-A671-F08746ABB021
# Cacti remote_agent.php Remote command execution vulnerability CVE-2022-46169

## Vulnerability Description

Cacti is a server monitoring and management platform. There is a command injection vulnerability in versions 1.2.17–1.2.22 of Cacti. Attackers can bypass server-side checks through the X-Forwarded-For request header and execute arbitrary commands within the system.

## Affected Versions

Cacti < 1.2.17–1.2.22

## Network Mapping

app="Cacti-monitoring-platform"

## Vulnerability Reproducibility
![J4%C_K RW2 KPS`T2B{39JT](https://github.com/a1665454764/CVE-2022-46169/assets/143511005/00938a15-c4de-4f87-ae0d-ee5c679a6058)
![J)8}@3I3VQ86W(WN` P1$LY](https://github.com/a1665454764/CVE-2022-46169/assets/143511005/f41b6cc5-d690-4aed-97ab-3637d785d94f)