Cacti v1.2.8 is susceptible to remote code execution. This vulnerability could be exploited without authentication if "Guest Realtime Graphs" privileges are enabled.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view