Home / exploitsPDF  

Cacti pollers.php SQL Injection / Remote Code Execution

Posted on 14 February 2024

This Metasploit exploit module leverages sql injection and local file inclusion vulnerabilities in Cacti versions prior to 1.2.26 to achieve remote code execution. Authentication is needed and the account must have access to the vulnerable PHP script (pollers.php). This is granted by setting the Sites/Devices/Data permission in the General Administration section.

 

TOP