Nagios

Nagios

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.87%
  • Veröffentlicht 09.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:16

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson....

  • EPSS 7.33%
  • Veröffentlicht 16.03.2020 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:36:00

Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is ...

  • EPSS 0.87%
  • Veröffentlicht 16.03.2020 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:36:00

Nagios Log Server 2.1.3 has CSRF.

  • EPSS 0.48%
  • Veröffentlicht 16.03.2020 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:36:00

Nagios Log Server 2.1.3 has Incorrect Access Control.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 28.02.2020 14:15:09
  • Zuletzt bearbeitet 21.11.2024 04:42:21

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges...

Exploit
  • EPSS 1.12%
  • Veröffentlicht 01.08.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 02:59:44

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the file...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 12.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:47:06

qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

  • EPSS 0.11%
  • Veröffentlicht 23.08.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a roo...

  • EPSS 0.35%
  • Veröffentlicht 06.06.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.

  • EPSS 0.59%
  • Veröffentlicht 31.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in Nagios.