PoC Index

CVE-2020-14295

HIGH 7.2EPSS 86.3%

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
86.33% chance of exploitation in the next 30 days, 100th percentile
Nuclei
high · CWE-89
Published
2020-06-17
Updated
2024-08-04

Proof-of-concept exploits (4)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

Exploit collections (1)

References

Related