Quantcast
Channel: Files from Christophe de la Fuente ≈ Packet Storm
Viewing all articles
Browse latest Browse all 17

Cacti pollers.php SQL Injection / Remote Code Execution

$
0
0
This Metasploit exploit module leverages sql injection and local file inclusion vulnerabilities in Cacti versions prior to 1.2.26 to achieve remote code execution. Authentication is needed and the account must have access to the vulnerable PHP script (pollers.php). This is granted by setting the Sites/Devices/Data permission in the General Administration section.

Viewing all articles
Browse latest Browse all 17

Latest Images

Trending Articles





Latest Images