Overview :
PRTG Network Monitor before allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.




Remote unauthenticated user can craft an HTTP request in /public/login.htm or /index.htm by providing the ‘type’ parameter.


replace cpuload by any of the following to get diferent info

  • version
  • cpuload
  • dnsname
  • serverhttpurl
  • windowsversion
  • systemid
  • treestat
  • memory
  • requests
  • screenshot
  • lastsync
  • probes
  • warnings