Cacti 1.2.22, vulnerable to CVE-2022-46169: remote_agent.php authorizes callers by a client address taken from headers such as X-Forwarded-For, and its polldata action puts poller_id into a shell command for data sources using the script server, so an unauthenticated request runs commands.
Pas commencéDockercommit 944e0f3x86_64 · aarch64Secret
Exploit CVE-2022-46169 to run commands on the Cacti server without logging in and get a shell.
Le brief de ce lab se trouve dans son dépôt.