Description
Due to an authorization bypass vulnerability in the remote agent handling in Cacti, au unauthenticated attacker can execute arbitrary OS commands with a specially crafted HTTP request.
Remediation
Upgrade to the latest version of Cacti
References
Related Vulnerabilities
phpMyFAQ Incorrect Authorization Vulnerability (CVE-2024-22208)
MyBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-43281)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4608)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3092)