Show filters
185 Total Results
Displaying 81-90 of 185
Sort by:
Attacker Value
Unknown

CVE-2020-28648

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.
Attacker Value
Unknown

CVE-2020-5796

Disclosure Date: November 13, 2020 (last updated February 22, 2025)
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privileges.
Attacker Value
Unknown

CVE-2020-5791

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.
Attacker Value
Unknown

CVE-2020-5792

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.
Attacker Value
Unknown

CVE-2020-5790

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
Attacker Value
Unknown

CVE-2020-15903

Disclosure Date: September 09, 2020 (last updated November 28, 2024)
An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3.
Attacker Value
Unknown

CVE-2020-16157

Disclosure Date: July 30, 2020 (last updated February 21, 2025)
A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
Attacker Value
Unknown

CVE-2020-15902

Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
Attacker Value
Unknown

CVE-2020-15901

Disclosure Date: July 22, 2020 (last updated November 28, 2024)
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
Attacker Value
Unknown

CVE-2020-13977

Disclosure Date: June 09, 2020 (last updated February 21, 2025)
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.