Cacti is an open-source PHP application for polling devices (largely over SNMP) and graphing the results, commonly deployed under /cacti/. It matters offensively for two reasons: it has a persistent history of serious web vulnerabilities, unauthenticated and authenticated command injection and SQL injection in its data-collection and graphing components, several reaching remote code execution on the server, and it stores the credentials it uses to poll devices (SNMP community strings, and SSH/other credentials for data sources), so compromising it harvests estate credentials. The surface is the login (default admin/admin), the known exploit chains, and the stored credential harvest.
curl -sk https://<target>/cacti/ | grep -ioE 'Version [0-9.]+' # fingerprint
Subtopics#
- Enumeration: product and version fingerprinting.
- Authentication: the default admin and weak credentials.
- Known exploits: the SQLi and command-injection RCE chains.
- Credential harvesting: stored SNMP strings and device credentials.