Show filters
155 Total Results
Displaying 91-100 of 155
Sort by:
Attacker Value
Unknown

CVE-2019-9164

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
Attacker Value
Unknown

CVE-2018-18245

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
0
Attacker Value
Unknown

CVE-2018-20171

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
0
Attacker Value
Unknown

CVE-2018-20172

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
0
Attacker Value
Unknown

CVE-2018-15708

Disclosure Date: November 14, 2018 (last updated October 06, 2023)
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
0
Attacker Value
Unknown

CVE-2018-15712

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
0
Attacker Value
Unknown

CVE-2018-15709

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
0
Attacker Value
Unknown

CVE-2018-15713

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
0
Attacker Value
Unknown

CVE-2018-15710

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
0
Attacker Value
Unknown

CVE-2018-15711

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.
0