Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7237

Опубликовано: 20 янв. 2020
Источник: debian
EPSS Средний

Описание

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.2.9+ds1-1package
cactifixed1.2.2+ds1-2+deb10u3busterpackage
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage

Примечания

  • https://github.com/Cacti/cacti/issues/3201

  • https://github.com/Cacti/cacti/commit/5010719dbd160198be3e07bb994cf237e3af1308

EPSS

Процентиль: 98%
0.46813
Средний

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.

CVSS3: 8.8
nvd
около 6 лет назад

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.

github
больше 3 лет назад

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 98%
0.46813
Средний