High severity8.8NVD Advisory· Published Feb 22, 2020· Updated Jun 17, 2026
CVE-2020-8813
CVE-2020-8813
Description
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16=1.2.8+ 1 more
- (no CPE)range: =1.2.8
- cpe:2.3:a:cacti:cacti:1.2.8:*:*:*:*:*:*:*
- Cacti/Cactidescription
- osv-coords7 versionspkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012pkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.1
< 1.2.18-1.2+ 6 more
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 1.2.11-bp151.4.6.1
- (no CPE)range: < 1.2.11-bp151.4.6.1
- (no CPE)range: < 1.2.11-5.1
- (no CPE)range: < 1.2.11-2.1
- (no CPE)range: < 1.2.11-5.1
- (no CPE)range: < 1.2.11-2.1
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:a:opmantek:open-audit:3.3.1:*:*:*:-:*:*:*
- cpe:2.3:o:opensuse:suse_package_hub:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
16- lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.htmlnvdExploitThird Party Advisory
- drive.google.com/file/d/1A8hxTyk_NgSp04zPX-23nPbsSDeyDFio/viewnvdExploitThird Party Advisory
- gist.github.com/mhaskar/ebe6b74c32fd0f7e1eedf1aabfd44129nvdExploitThird Party Advisory
- shells.systems/cacti-v1-2-8-authenticated-remote-code-execution-cve-2020-8813/nvdExploitThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.htmlnvdMailing ListThird Party Advisory
- packetstormsecurity.com/files/156537/Cacti-1.2.8-Unauthenticated-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/156538/Cacti-1.2.8-Authenticated-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/156593/Cacti-1.2.8-Unauthenticated-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/157477/Open-AudIT-Professional-3.3.1-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB Entry
- github.com/Cacti/cacti/issues/3285nvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/12/msg00039.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202004-16nvdThird Party Advisory
- github.com/Cacti/cacti/releasesnvdRelease Notes
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M77SS33IDVNGBU566TK2XVULPW3RXUQ4/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WAX3LDXPIKWNBGVZSIMZV7LI5K6BZRTO/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XEMDQXDRNQYXOME7TACKDVCXZXZNGZE2/nvd
News mentions
0No linked articles in our index yet.