Nagios

Nagios

37 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.87%
  • Published 09.06.2020 14:15:10
  • Last modified 21.11.2024 05:02:16

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson....

  • EPSS 7.33%
  • Published 16.03.2020 16:15:14
  • Last modified 21.11.2024 05:36:00

Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is ...

  • EPSS 0.87%
  • Published 16.03.2020 16:15:14
  • Last modified 21.11.2024 05:36:00

Nagios Log Server 2.1.3 has CSRF.

  • EPSS 0.48%
  • Published 16.03.2020 16:15:14
  • Last modified 21.11.2024 05:36:00

Nagios Log Server 2.1.3 has Incorrect Access Control.

Exploit
  • EPSS 0.18%
  • Published 28.02.2020 14:15:09
  • Last modified 21.11.2024 04:42:21

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges...

Exploit
  • EPSS 1.12%
  • Published 01.08.2018 14:29:00
  • Last modified 21.11.2024 02:59:44

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the file...

Exploit
  • EPSS 0.22%
  • Published 12.07.2018 18:29:00
  • Last modified 21.11.2024 03:47:06

qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

  • EPSS 0.11%
  • Published 23.08.2017 21:29:00
  • Last modified 20.04.2025 01:37:25

Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a roo...

  • EPSS 0.35%
  • Published 06.06.2017 18:29:00
  • Last modified 20.04.2025 01:37:25

The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.

  • EPSS 0.59%
  • Published 31.03.2017 16:59:00
  • Last modified 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in Nagios.