References https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/CactiEZ-weathermap-%E6%8F%92%E4%BB%B6%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://blog.csdn.net/m0_46689007/article/details/128106529 https://www.cnvd.org.cn/flaw/show/CNVD-2016-12935 http://wooyun.2xss.cc/bug_detail.php?wybug_id=wooyun-2016-0178883 https://cn-sec.com/archives/39297.html https://masterxsec.github.io/2018/04/09/CactiEZ-weathermap%E6%8F%92%E4%BB%B6%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5/ https://github.com/Threekiii/Awesome-POC https://avd.aliyun.com/detail?id=AVD-2021-913819 https://qkl.seebug.org/vuldb/ssvid-91028 https://gist.github.com/gerry/d977490319a474b9d777538452018b54 https://s4e.io/tools/cacti-weathermap-arbitrary-file-write https://www.exploit-db.com/exploits/26125
Related VulnerabilitiesPoCcacti-guest-access-enabled: Cacti - Guest User Access EnabledPoCcacti-log-exposure: Cacti Log - ExposurePoCcacti-fpd: Cacti - Full Path DisclosurePoCCVE-2020-8813: Cacti v1.2.8 - Remote Code ExecutionPoCCVE-2021-26247: Cacti - Cross-Site ScriptingPoCCVE-2022-46169: Cacti <=1.2.22 - Remote Command InjectionPoCCVE-2023-30534: Cacti < 1.2.25 Insecure DeserializationPoCCVE-2023-39361: Cacti 1.2.24 - SQL InjectionPoCCVE-2024-29895: Cacti cmd_realtime.php - Command InjectionPoCCVE-2022-46169: Cacti remote_agent.php 远程命令执行漏洞PoCcacti-weathermap-file-write: Cacti Weathermap File Write浙大恩特客户资源管理系统 /entsoft/CrmBasicAction.entcrm 文件上传漏洞 (CNVD-2021-51371)