Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-49084

Опубликовано: 21 дек. 2023
Источник: debian
EPSS Высокий

Описание

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `link.php`. Impact of the vulnerability execution of arbitrary code on the server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.2.26+ds1-1package

Примечания

  • https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp

  • https://github.com/Cacti/cacti/commit/5f451bc680d7584525d18026836af2a1e31b2188 (release/1.2.26)

  • https://github.com/Cacti/cacti/commit/c3a647e9867ae8e2982e26342630ba9edb2d94b7 (release/1.2.26)

  • Mitigated in Debian by not shipping or creating 'include/content/'

EPSS

Процентиль: 99%
0.88341
Высокий

Связанные уязвимости

CVSS3: 8
ubuntu
около 2 лет назад

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `link.php`. Impact of the vulnerability execution of arbitrary code on the server.

CVSS3: 8
nvd
около 2 лет назад

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `link.php`. Impact of the vulnerability execution of arbitrary code on the server.

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость сценария link.php программного средства мониторинга сети Cacti, позволяющая нарушителю выполнить произвольный код

suse-cvrf
около 2 лет назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 99%
0.88341
Высокий