CVE-2020-14295
CVE-2020-14295
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.
Productos afectados
n/a · n/aPoCs públicas encontradas — 5
githubgithub.com/0z09e/CVE-2020-14295★ 2githubgithub.com/mrg3ntl3m4n/CVE-2020-14295★ 0cve_referencepacketstormsecurity.com/files/162384/Cacti-1.2.12-SQL-Injection-Remote-Code-Execution.htmlno verificadocve_referencepacketstormsecurity.com/files/162918/Cacti-1.2.12-SQL-Injection-Remote-Command-Execution.htmlno verificadoexploitdbwww.exploit-db.com/exploits/49810no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.htmlhttp://packetstormsecurity.com/files/162384/Cacti-1.2.12-SQL-Injection-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/162918/Cacti-1.2.12-SQL-Injection-Remote-Command-Execution.htmlhttps://github.com/Cacti/cacti/issues/3622https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W64CIB6L4HZRVQSWKPDDKXJO4J2XTOXD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKM5G3YNSZDHDZMPCMAHG5B5M2V4XYSE/https://security.gentoo.org/glsa/202007-03