CVE-2023-38349
- EPSS 0.1%
- Published 15.07.2023 02:15:08
- Last modified 21.11.2024 08:13:23
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
CVE-2023-38350
- EPSS 0.12%
- Published 15.07.2023 02:15:08
- Last modified 21.11.2024 08:13:23
PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.
CVE-2017-16834
- EPSS 0.04%
- Published 16.11.2017 02:29:05
- Last modified 20.04.2025 01:37:25
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.
CVE-2014-4907
- EPSS 0.43%
- Published 11.07.2014 11:08:22
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.
CVE-2014-4908
- EPSS 0.31%
- Published 11.07.2014 11:08:22
- Last modified 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/applic...
CVE-2012-3457
- EPSS 0.05%
- Published 12.08.2012 00:55:00
- Last modified 11.04.2025 00:51:21
PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file.