five

Cacti 1.2.24 - SQL Injection (CVE-2023-39361)

收藏
pentest-tools.com2025-03-26 收录
下载链接:
https://pentest-tools.com/vulnerabilities-exploits/undefined
下载链接
链接失效反馈
官方服务:
资源简介:
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Cacti是一款开源的运营监控与故障管理框架。受影响版本存在一个在graph_view.php中发现的SQL注入漏洞。鉴于访客用户默认无需身份验证即可访问graph_view.php,若启用访客用户功能,则可能造成重大损害。攻击者可能利用此漏洞,存在篡夺管理权限或远程代码执行等行为的风险。该问题已在版本1.2.25中得到解决。建议用户升级。目前尚未发现针对此漏洞的已知解决方案。
提供机构:
pentest-tools.com
5,000+
优质数据集
54 个
任务类型
进入经典数据集
二维码
社区交流群

面向社区/商业的数据集话题

二维码
科研交流群

面向高校/科研机构的开源数据集话题

数据驱动未来

携手共赢发展

商业合作