CVE-2018-15711
- EPSS 31.73%
- Veröffentlicht 14.11.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:19
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.
CVE-2018-15712
- EPSS 26.77%
- Veröffentlicht 14.11.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:19
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
CVE-2018-15713
- EPSS 3.71%
- Veröffentlicht 14.11.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:19
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
CVE-2018-15714
- EPSS 21.37%
- Veröffentlicht 14.11.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:19
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
CVE-2018-10735
- EPSS 86.27%
- Veröffentlicht 16.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:57
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
CVE-2018-10736
- EPSS 83.16%
- Veröffentlicht 16.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:57
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
CVE-2018-10737
- EPSS 83.16%
- Veröffentlicht 16.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:57
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
CVE-2018-10738
- EPSS 66.85%
- Veröffentlicht 16.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:57
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
CVE-2018-10553
- EPSS 3.14%
- Veröffentlicht 30.04.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:33
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.
CVE-2018-10554
- EPSS 2.18%
- Veröffentlicht 30.04.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:33
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, relat...