CVE Database
/

CVE-2020-7237

Back to search

CVE-2020-7237

Published: Jan 20, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2020-0fc6dd0fd2
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-90f1c8229e
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2020:0272
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0284
vendor-advisory
x_refsource_SUSE
GLSA-202003-40
vendor-advisory
x_refsource_GENTOO
openSUSE-SU-2020:0558
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:0565
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now