postData="tab=path&path_rrdtool=touch%20/tmp/CVE-2017-16641&action=save&path_snmpwalk=/usr/bin/snmpwalk&path_snmpget=/usr/bin/snmpget&path_snmpbulkwalk=/usr/bin/snmpbulkwalk&path_snmpgetnext=/usr/bin/snmpgetnext&path_snmptrap=/usr/bin/snmptrap&path_php_binary=/usr/bin/php&path_cactilog=/var/log/cacti/cacti.log&logrotate_retain=7&path_spine=/usr/sbin/spine&path_spine_config=/etc/cacti/spine.conf&rrd_autoclean_method=1&rrd_achive=/usr/share/cacti/site/rra/archive/&__csrf_magic=${magic}"
wget --output-document="$tmpFile1" $loadSaveCookie --post-data="$postData" http://localhost/cacti/settings.php
# TODO [elbrus]: as we don't have any sources, I don't think this still works as intended
# Need to run the cron for this to show up
php /usr/share/cacti/site/poller.php
if [ -f /tmp/CVE-2017-16641 ] ; then
    echo "/tmp/CVE-2017-16641 found"
    exit 179
fi
