VDB
CVE-2020-8813
CVE-2020-8813
PUBLISHED
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
EPSS 93.59% · 99.8th percentile
Risk Scores
EPSS Score
93.59%
99.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:18.04:LTS | cacti | *, 1.1.27+ds1-2, 1.1.35+ds1-1 |
| Ubuntu:Pro:14.04:LTS | cacti | 0.8.8b+dfsg-3, 0.8.8b+dfsg-5, 0.8.8b+dfsg-5ubuntu0.1 |
Exploit Intelligence
- 0xm4ud/Cacti-CVE-2020-8813 (github-poc-repo)
- 0xm4ud/Cacti-CVE-2020-8813 (github-poc-repo)
- 0xm4ud/Cacti-CVE-2020-8813 (github-poc-repo)
- 0xm4ud/Cacti-CVE-2020-8813 (github-poc-repo)
- 0xm4ud/Cacti-CVE-2020-8813 (github-poc-repo)
- 0xm4ud/Cacti-CVE-2020-8813 (github-poc-repo)
- 0xm4ud/Cacti-CVE-2020-8813 (github-poc-repo)
- 0xm4ud/Cacti-CVE-2020-8813 (github-poc-repo)
- 0xm4ud/Cacti-CVE-2020-8813 (github-poc-repo)
- Cacti v1.2.8 Unauthenticated Remote Code Execution (github-poc-repo)
…and 92 more exploits
Timeline
- Feb 22, 2020 CVE Published
- Feb 24, 2020 PoC Published
- Feb 27, 2020 PoC Published
- Mar 2, 2020 PoC Published
- Apr 30, 2020 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-8813 third-party-advisory
- https://gist.github.com/mhaskar/ebe6b74c32fd0f7e1eedf1aabfd44129 third-party-advisory
- https://shells.systems/cacti-v1-2-8-authenticated-remote-code-execution-cve-2020-8813/ third-party-advisory
- https://github.com/Cacti/cacti/issues/3285 third-party-advisory
- https://github.com/Cacti/cacti/commit/fea919e8fe05bb730c802054661fd3a7ec029784 third-party-advisory
- https://drive.google.com/file/d/1A8hxTyk_NgSp04zPX-23nPbsSDeyDFio/view third-party-advisory
- https://github.com/Cacti/cacti/releases third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8813 third-party-advisory