Search: "nagios"

320 CVEs found

CVE-2002-1959
10.0 HIGH

Nagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.

Published: 2002-12-31
Products: 3
Vendors:
nagios
CVE-2006-2162
5.0 MEDIUM

Buffer overflow in CGI scripts in Nagios 1.x before 1.4 and 2.x before 2.3 allows remote attackers to execute arbitrary code via a negative content length (Content-Length) HTTP header.

Published: 2006-05-03
Products: 2
Vendors:
nagios

Integer overflow in CGI scripts in Nagios 1.x before 1.4.1 and 2.x before 2.3.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a content length (C...

Published: 2006-05-19
Products: 23
Vendors:
nagios

PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][physical] parameter.

Published: 2007-05-16
Products: 1
Vendors:
nagiosql

PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][IT] parameter. ...

Published: 2007-05-16
Products: 1
Vendors:
nagiosql
CVE-2007-5198
6.8 MEDIUM

Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web servers to execute arbitrary code via Location header...

Published: 2007-10-04
Products: 1
Vendors:
nagios
CVE-2007-5623
5.0 MEDIUM

Buffer overflow in the check_snmp function in Nagios Plugins (nagios-plugins) 1.4.10 allows remote attackers to cause a denial of service (crash) via crafted snmpget replies.

Published: 2007-10-23
Products: 1
Vendors:
nagios
CVE-2007-5624
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Nagios 2.x before 2.10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts.

Published: 2007-10-23
Products: 1
Vendors:
nagios
CVE-2008-1360
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Nagios before 2.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts, a different issue than CVE...

Published: 2008-03-17
Products: 7
Vendors:
nagios
CVE-2007-5803
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in CGI programs in Nagios before 2.12 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue...

Published: 2008-05-13
Products: 31
Vendors:
nagios
CVE-2008-5027
6.5 MEDIUM

The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization checks, and trigger execution of arbitrary programs by this pro...

Published: 2008-11-10
Products: 65
Vendors:
op5 nagios
CVE-2008-5028
6.8 MEDIUM

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of...

Published: 2008-11-10
Products: 65
Vendors:
op5 nagios
CVE-2008-6373
5.0 MEDIUM

Unspecified vulnerability in Nagios before 3.0.6 has unspecified impact and remote attack vectors related to CGI programs, "adaptive external commands," and "writing newlines and submitting service co...

Published: 2009-03-02
Products: 55
Vendors:
nagios

statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.

Published: 2009-07-01
Products: 32
Vendors:
nagios
CVE-2010-3616
5.0 MEDIUM

ISC DHCP server 4.2 before 4.2.0-P2, when configured to use failover partnerships, allows remote attackers to cause a denial of service (communications-interrupted state and DHCP client service loss) ...

Published: 2010-12-17
Products: 2
Vendors:
isc
CVE-2011-1523
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter.

Published: 2011-05-03
Products: 63
Vendors:
nagios
CVE-2011-2179
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expa...

Published: 2011-06-14
Products: 16
Vendors:
icinga nagios

Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow rem...

Published: 2013-01-22
Products: 44
Vendors:
icinga nagios

The Foundation webapp admin interface in GroundWork Monitor Enterprise 6.7.0 uses the nagios account as the owner of writable files under /usr/local/groundwork, which allows context-dependent attacker...

Published: 2013-05-08
Products: 1
Vendors:
gwos
CVE-2013-3504
5.5 MEDIUM

Directory traversal vulnerability in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to overwrite arbitrary files by leveraging access to ...

Published: 2013-05-08
Products: 1
Vendors:
gwos