RaXnet Cacti Graph_Image.PHP Remote Command Execution Vulnerability
BID:14042
Info
RaXnet Cacti Graph_Image.PHP Remote Command Execution Vulnerability
| Bugtraq ID: | 14042 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2005 12:00AM |
| Updated: | Jun 23 2005 12:00AM |
| Credit: | Discovery is credited to Alberto Trivero <[email protected]>. |
| Vulnerable: |
Raxnet Cacti 0.8.6 d Raxnet Cacti 0.8.6 c Raxnet Cacti 0.8.6 b Raxnet Cacti 0.8.6 a Raxnet Cacti 0.8.6 Raxnet Cacti 0.8.5 a Raxnet Cacti 0.8.5 Raxnet Cacti 0.8.4 Raxnet Cacti 0.8.3 a Raxnet Cacti 0.8.3 Raxnet Cacti 0.8.2 a Raxnet Cacti 0.8.2 Raxnet Cacti 0.8.1 Raxnet Cacti 0.8 Raxnet Cacti 0.6.8 a Raxnet Cacti 0.6.8 Raxnet Cacti 0.6.7 Raxnet Cacti 0.6.6 Raxnet Cacti 0.6.5 Raxnet Cacti 0.6.4 Raxnet Cacti 0.6.3 Raxnet Cacti 0.6.2 Raxnet Cacti 0.6.1 Raxnet Cacti 0.6 Raxnet Cacti 0.5 |
| Not Vulnerable: | |
Discussion
RaXnet Cacti Graph_Image.PHP Remote Command Execution Vulnerability
Cacti is prone to a remote command execution vulnerability.
User-supplied input to the 'graph_image.php' script is not properly sanitized and allows attackers to execute arbitrary commands in the context of the server.
This can facilitate various attacks including unauthorized access to an affected computer.
Cacti 0.8.6d and prior versions are reportedly affected.
Cacti is prone to a remote command execution vulnerability.
User-supplied input to the 'graph_image.php' script is not properly sanitized and allows attackers to execute arbitrary commands in the context of the server.
This can facilitate various attacks including unauthorized access to an affected computer.
Cacti 0.8.6d and prior versions are reportedly affected.
Exploit / POC
RaXnet Cacti Graph_Image.PHP Remote Command Execution Vulnerability
An exploit is not required.
A Metasploit exploit cacti_graphimage_exec.pm is available:
The following proof of concept examples are available:
http://www.example.com/cacti/graph_image.php?local_graph_id=[valid_value]&gr
aph_start=%0a[command]%0a
An exploit is not required.
A Metasploit exploit cacti_graphimage_exec.pm is available:
The following proof of concept examples are available:
http://www.example.com/cacti/graph_image.php?local_graph_id=[valid_value]&gr
aph_start=%0a[command]%0a
Solution / Fix
RaXnet Cacti Graph_Image.PHP Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
RaXnet Cacti Graph_Image.PHP Remote Command Execution Vulnerability
References:
References:
- Cacti Homepage (Cacti)
- Remote Command Execution Exploit for Cacti <= 0.8.6d ("Alberto Trivero"
)