Back to search
CVE-2020-7237
Published: Jan 20, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/Cacti/cacti/issues/3201
x_refsource_MISC
FEDORA-2020-0fc6dd0fd2
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-90f1c8229e
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2020:0272
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0284
vendor-advisory
x_refsource_SUSE
GLSA-202003-40
vendor-advisory
x_refsource_GENTOO
openSUSE-SU-2020:0558
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0565
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now