Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2023-38350

Disclosure Date: July 15, 2023 (last updated October 08, 2023)
PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.
Attacker Value
Unknown

CVE-2023-38349

Disclosure Date: July 15, 2023 (last updated October 08, 2023)
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
Attacker Value
Unknown

CVE-2017-16834

Disclosure Date: November 16, 2017 (last updated November 26, 2024)
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.
0
Attacker Value
Unknown

CVE-2014-4908

Disclosure Date: July 11, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element.
0
Attacker Value
Unknown

CVE-2014-4907

Disclosure Date: July 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.
0
Attacker Value
Unknown

CVE-2012-3457

Disclosure Date: August 12, 2012 (last updated October 04, 2023)
PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file.
0