Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-105678. PoCs published by Alberto Trivero.
AI-analyzed exploit summary This Perl script exploits a command injection vulnerability in Cacti <= 0.8.6d by injecting shell commands via the 'graph_start' parameter in graph_image.php. It retrieves a valid local_graph_id, then sends a crafted request to execute arbitrary commands, including downloading and running a remote shell script.
Description
Cacti 0.8.6d - Remote Command Execution
Exploits (1)
This Perl script exploits a command injection vulnerability in Cacti <= 0.8.6d by injecting shell commands via the 'graph_start' parameter in graph_image.php. It retrieves a valid local_graph_id, then sends a crafted request to execute arbitrary commands, including downloading and running a remote shell script.