Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38483
HistoryDec 15, 2022 - 1:51 a.m.

Command Injection

2022-12-1501:51:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
command injection
authorization bypass
php.

0.964 High

EPSS

Percentile

99.6%

cacti is vulnerable to command injection. Authorization can be bypassed due to the implementation of the get_client_addr function. The function is defined in the file lib/functions.php and checks serval $_SERVER variables to determine the IP address of the client which allows an attacker to set arbitrarily variables beginning with HTTP_.