Show filters
185 Total Results
Displaying 161-170 of 185
Sort by:
Attacker Value
Unknown
CVE-2013-7205
Disclosure Date: January 15, 2014 (last updated October 05, 2023)
Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list, which triggers a heap-based buffer over-read.
0
Attacker Value
Unknown
CVE-2013-6039
Disclosure Date: December 09, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in NagiosQL 3.2 SP2 allow remote attackers to inject arbitrary web script or HTML via the txtSearch parameter to (1) admin/hostdependencies.php, (2) admin/hosts.php, or other unspecified pages that allow search input, related to the search functionality in functions/content_class.php.
0
Attacker Value
Unknown
CVE-2013-6875
Disclosure Date: November 26, 2013 (last updated October 05, 2023)
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.
0
Attacker Value
Unknown
CVE-2013-4214
Disclosure Date: November 23, 2013 (last updated October 05, 2023)
rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache.
0
Attacker Value
Unknown
CVE-2013-1362
Disclosure Date: July 09, 2013 (last updated October 05, 2023)
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
0
Attacker Value
Unknown
CVE-2012-6096
Disclosure Date: January 22, 2013 (last updated October 05, 2023)
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.
0
Attacker Value
Unknown
CVE-2012-3457
Disclosure Date: August 12, 2012 (last updated October 04, 2023)
PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file.
0
Attacker Value
Unknown
CVE-2011-2179
Disclosure Date: June 14, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.
0
Attacker Value
Unknown
CVE-2011-1523
Disclosure Date: May 03, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter.
0
Attacker Value
Unknown
CVE-2009-4626
Disclosure Date: January 18, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the conf[lang] parameter.
0