Nagios

Nagios Xi

110 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 8.32%
  • Published 30.12.2019 15:15:10
  • Last modified 21.11.2024 04:38:04

In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.

Warning Exploit
  • EPSS 90.14%
  • Published 05.09.2019 17:15:12
  • Last modified 07.03.2025 14:24:42

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profil...

  • EPSS 6.7%
  • Published 10.07.2019 14:15:10
  • Last modified 21.11.2024 03:53:57

Nagios XI before 5.5.4 has XSS in the auto login admin management page.

  • EPSS 6.36%
  • Published 19.06.2019 18:15:11
  • Last modified 21.11.2024 03:53:57

A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin...

  • EPSS 0.36%
  • Published 19.06.2019 18:15:11
  • Last modified 21.11.2024 03:53:57

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidentia...

Exploit
  • EPSS 25.4%
  • Published 22.05.2019 16:29:01
  • Last modified 21.11.2024 04:22:33

Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection...

  • EPSS 0.04%
  • Published 28.03.2019 20:29:01
  • Last modified 21.11.2024 04:51:07

Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.

Exploit
  • EPSS 14.22%
  • Published 28.03.2019 20:29:01
  • Last modified 21.11.2024 04:51:07

Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.

Exploit
  • EPSS 6.63%
  • Published 28.03.2019 19:29:02
  • Last modified 21.11.2024 04:51:07

SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.

Exploit
  • EPSS 65.67%
  • Published 28.03.2019 17:29:01
  • Last modified 21.11.2024 04:51:07

Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.