Search: "nagios"

320 CVEs found

CVE-2018-17146
5.4 MEDIUM

A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arb...

Published: 2019-06-19
Products: 1
Vendors:
nagios
CVE-2018-17148
9.8 CRITICAL

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain ac...

Published: 2019-06-19
Products: 1
Vendors:
nagios
CVE-2018-17147
4.8 MEDIUM

Nagios XI before 5.5.4 has XSS in the auto login admin management page.

Published: 2019-07-10
Products: 1
Vendors:
nagios
CVE-2019-15898
6.1 MEDIUM

Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.

Published: 2019-09-03
Products: 1
Vendors:
nagios

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh scrip...

Published: 2019-09-05
Products: 1
Vendors:
nagios
CVE-2019-20139
5.4 MEDIUM

In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin u...

Published: 2019-12-30
Products: 1
Vendors:
nagios

In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.

Published: 2019-12-31
Products: 1
Vendors:
nagios
CVE-2019-20384
5.5 MEDIUM

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is wr...

Published: 2020-01-21
Products: 1
Vendors:
gentoo
CVE-2019-3698
5.7 MEDIUM

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to ...

Published: 2020-02-28
Products: 6
Vendors:
suse opensuse nagios
CVE-2020-6584
6.5 MEDIUM

Nagios Log Server 2.1.3 has Incorrect Access Control.

Published: 2020-03-16
Products: 1
Vendors:
nagios

Nagios Log Server 2.1.3 has CSRF.

Published: 2020-03-16
Products: 1
Vendors:
nagios
CVE-2020-6586
5.4 MEDIUM

Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload i...

Published: 2020-03-16
Products: 1
Vendors:
nagios

Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injecti...

Published: 2020-03-16
Products: 2
Vendors:
fedoraproject nagios

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

Published: 2020-03-16
Products: 2
Vendors:
fedoraproject nagios
CVE-2020-10819
4.8 MEDIUM

Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.

Published: 2020-03-22
Products: 1
Vendors:
nagios
CVE-2020-10820
4.8 MEDIUM

Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.

Published: 2020-03-22
Products: 1
Vendors:
nagios
CVE-2020-10821
4.8 MEDIUM

Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.

Published: 2020-03-22
Products: 1
Vendors:
nagios
CVE-2020-13977
4.9 MEDIUM

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of th...

Published: 2020-06-09
Products: 4
Vendors:
fedoraproject nagios
CVE-2020-7206
9.8 CRITICAL

HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.

Published: 2020-07-17
Products: 1
Vendors:
hp

In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.

Published: 2020-07-22
Products: 1
Vendors:
nagios