Show filters
155 Total Results
Displaying 81-90 of 155
Sort by:
Attacker Value
Unknown

CVE-2019-20197

Disclosure Date: December 31, 2019 (last updated November 27, 2024)
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
Attacker Value
Unknown

CVE-2019-15949

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.
Attacker Value
Unknown

CVE-2018-17147

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Nagios XI before 5.5.4 has XSS in the auto login admin management page.
0
Attacker Value
Unknown

CVE-2019-20139

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
Attacker Value
Unknown

CVE-2018-17146

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page.
0
Attacker Value
Unknown

CVE-2018-17148

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.
0
Attacker Value
Unknown

CVE-2019-12279

Disclosure Date: May 22, 2019 (last updated November 08, 2023)
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any valid injection that can be done with the variable provided, and while the username value being passed does get used in a SQL query, it is passed through SQL escaping functions when creating the call. The vendor tried re-creating the issue with no luck
0
Attacker Value
Unknown

CVE-2019-9166

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.
Attacker Value
Unknown

CVE-2019-9167

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
Attacker Value
Unknown

CVE-2019-9165

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.