Show filters
155 Total Results
Displaying 101-110 of 155
Sort by:
Attacker Value
Unknown

CVE-2018-15714

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
0
Attacker Value
Unknown

CVE-2016-8641

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.
0
Attacker Value
Unknown

CVE-2018-13441

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
0
Attacker Value
Unknown

CVE-2018-13458

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
0
Attacker Value
Unknown

CVE-2018-13457

Disclosure Date: July 12, 2018 (last updated November 27, 2024)
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
0
Attacker Value
Unknown

CVE-2018-10735

Disclosure Date: May 16, 2018 (last updated November 26, 2024)
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
0
Attacker Value
Unknown

CVE-2018-10737

Disclosure Date: May 16, 2018 (last updated November 26, 2024)
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
0
Attacker Value
Unknown

CVE-2018-10736

Disclosure Date: May 16, 2018 (last updated November 26, 2024)
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
0
Attacker Value
Unknown

CVE-2018-10738

Disclosure Date: May 16, 2018 (last updated November 26, 2024)
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
0
Attacker Value
Unknown

CVE-2018-10553

Disclosure Date: April 30, 2018 (last updated November 26, 2024)
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.
0