CVE-2013-3504
- EPSS 1.85%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
Directory traversal vulnerability in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to overwrite arbitrary files by leveraging access to the nagios account.
- EPSS 1.45%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Nagios-App component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to bypass intended access restrictions via a direct request for a (1) log file or (2) configuration file.
CVE-2013-3506
- EPSS 2.51%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which allows remote attackers to execute arbitrary commands by creating a .shtml file and leveraging Server ...
- EPSS 1.34%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
The NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to obtain sensitive information via a direct request for (1) a configuration file, (2) a database dump, or (3) the Tomcat status context.
CVE-2013-3508
- EPSS 1.97%
- Veröffentlicht 08.05.2013 12:09:33
- Zuletzt bearbeitet 29.04.2026 01:13:23
html/System-Files.php in the System File Overview feature in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via vectors involving file editing.