Nagios

Nagios Xi

110 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1%
  • Published 28.09.2021 17:15:07
  • Last modified 21.11.2024 06:13:36

Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

  • EPSS 10.9%
  • Published 28.09.2021 17:15:07
  • Last modified 21.11.2024 06:13:36

Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

Exploit
  • EPSS 84.02%
  • Published 15.09.2021 14:15:08
  • Last modified 21.11.2024 06:16:30

In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

  • EPSS 0.02%
  • Published 13.08.2021 12:15:07
  • Last modified 21.11.2024 06:14:58

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.

  • EPSS 0.09%
  • Published 13.08.2021 12:15:07
  • Last modified 21.11.2024 06:14:59

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.

  • EPSS 11.69%
  • Published 13.08.2021 12:15:07
  • Last modified 21.11.2024 06:14:59

Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.

  • EPSS 0.16%
  • Published 13.08.2021 12:15:07
  • Last modified 21.11.2024 06:14:59

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.

  • EPSS 47.52%
  • Published 13.08.2021 12:15:07
  • Last modified 21.11.2024 06:14:59

Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

  • EPSS 0.58%
  • Published 13.08.2021 12:15:07
  • Last modified 21.11.2024 06:14:59

Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.

  • EPSS 3.25%
  • Published 13.08.2021 12:15:07
  • Last modified 21.11.2024 06:14:59

An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.