Nagios

Nagios Xi

110 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 83.57%
  • Published 16.05.2018 13:29:00
  • Last modified 21.11.2024 03:41:57

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.

Exploit
  • EPSS 83.57%
  • Published 16.05.2018 13:29:00
  • Last modified 21.11.2024 03:41:57

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.

Exploit
  • EPSS 83.57%
  • Published 16.05.2018 13:29:00
  • Last modified 21.11.2024 03:41:57

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.

  • EPSS 3.96%
  • Published 30.04.2018 03:29:00
  • Last modified 21.11.2024 03:41:33

An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.

Exploit
  • EPSS 2.18%
  • Published 30.04.2018 03:29:00
  • Last modified 21.11.2024 03:41:33

An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, relat...

Exploit
  • EPSS 77.71%
  • Published 18.04.2018 00:29:00
  • Last modified 21.11.2024 04:14:13

Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.

Exploit
  • EPSS 79.56%
  • Published 18.04.2018 00:29:00
  • Last modified 21.11.2024 04:14:13

SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.

Exploit
  • EPSS 75.22%
  • Published 18.04.2018 00:29:00
  • Last modified 21.11.2024 04:14:14

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

Exploit
  • EPSS 65.53%
  • Published 18.04.2018 00:29:00
  • Last modified 21.11.2024 04:14:14

A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.

Exploit
  • EPSS 19.74%
  • Published 26.11.2013 16:55:03
  • Last modified 11.04.2025 00:51:21

SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.