CVE-2013-3504
- EPSS 0.67%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to overwrite arbitrary files by leveraging access to the nagios account.
- EPSS 0.29%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Nagios-App component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to bypass intended access restrictions via a direct request for a (1) log file or (2) configuration file.
CVE-2013-3506
- EPSS 1.45%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which allows remote attackers to execute arbitrary commands by creating a .shtml file and leveraging Server ...
- EPSS 0.68%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
The NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to obtain sensitive information via a direct request for (1) a configuration file, (2) a database dump, or (3) the Tomcat status context.
CVE-2013-3508
- EPSS 0.61%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via vectors involving file editing.