Nagios

Nagios Xi

192 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Exploit
  • EPSS 93.71%
  • Veröffentlicht 15.02.2021 13:15:12
  • Zuletzt bearbeitet 03.11.2025 15:14:53

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by ...

Warnung Exploit
  • EPSS 60.59%
  • Veröffentlicht 15.02.2021 13:15:12
  • Zuletzt bearbeitet 03.11.2025 15:13:58

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single...

Warnung Exploit
  • EPSS 80.35%
  • Veröffentlicht 15.02.2021 13:15:12
  • Zuletzt bearbeitet 03.11.2025 15:13:53

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a si...

Exploit
  • EPSS 79.93%
  • Veröffentlicht 15.02.2021 13:15:12
  • Zuletzt bearbeitet 21.11.2024 05:54:42

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an...

  • EPSS 25.4%
  • Veröffentlicht 26.01.2021 18:16:28
  • Zuletzt bearbeitet 21.11.2024 06:21:06

Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.

Exploit
  • EPSS 86.67%
  • Veröffentlicht 13.01.2021 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:37

An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.

  • EPSS 5.95%
  • Veröffentlicht 16.11.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:22:09

Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).

  • EPSS 5.95%
  • Veröffentlicht 16.11.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:22:09

Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).

  • EPSS 30.19%
  • Veröffentlicht 16.11.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:22:09

Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).

  • EPSS 5.95%
  • Veröffentlicht 16.11.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:22:09

Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).