Nagios 漏洞列表
共找到 34 个与 Nagios 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2018-10735: NagiosXI <= 5.4.12 `commandline.php` SQL injection POC
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter. -
CVE-2018-10736: NagiosXI <= 5.4.12 - SQL injection POC
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter. -
CVE-2018-10737: NagiosXI <= 5.4.12 logbook.php SQL injection POC
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter. -
CVE-2018-10738: NagiosXI <= 5.4.12 menuaccess.php - SQL injection POC
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter. -
CVE-2021-25296: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25297: Nagios 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25298: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25299: Nagios XI 5.7.5 - Cross-Site Scripting POC
Nagios XI 5.7.5 contains a cross-site scripting vulnerability in the file /usr/local/nagiosxi/html/admin/sshterm.php, due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal session cookies, or it can be chained with the previous bugs to get one-click remote command execution on the Nagios XI server. -
CVE-2021-38156: Nagios XI < 5.8.6 - Cross-Site Scripting POC
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard. -
CVE-2022-29272: Nagios XI <5.8.5 - Open Redirect POC
Nagios XI through 5.8.5 contains an open redirect vulnerability in the login function. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. -
CVE-2023-40931: Nagios XI v5.11.0 - SQL Injection POC
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php. -
CVE-2023-48084: Nagios XI < 5.11.3 - SQL Injection POC
SQL injection vulnerability in Nagios XI before version 5.11.3 via the bulk modification tool. -
CVE-2018-10735: NagiosXI <= 5.4.12 `commandline.php` SQL injection POC
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter. -
CVE-2018-10736: NagiosXI <= 5.4.12 - SQL injection POC
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter. -
CVE-2018-10737: NagiosXI <= 5.4.12 logbook.php SQL injection POC
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter. -
CVE-2018-10738: NagiosXI <= 5.4.12 menuaccess.php - SQL injection POC
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter. -
CVE-2021-25296: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25297: Nagios 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25298: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25299: Nagios XI 5.7.5 - Cross-Site Scripting POC
Nagios XI 5.7.5 contains a cross-site scripting vulnerability in the file /usr/local/nagiosxi/html/admin/sshterm.php, due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal session cookies, or it can be chained with the previous bugs to get one-click remote command execution on the Nagios XI server. -
CVE-2021-38156: Nagios XI < 5.8.6 - Cross-Site Scripting POC
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard. -
CVE-2022-29272: Nagios XI <5.8.5 - Open Redirect POC
Nagios XI through 5.8.5 contains an open redirect vulnerability in the login function. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. -
CVE-2023-40931: Nagios XI v5.11.0 - SQL Injection POC
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php. -
CVE-2023-48084: Nagios XI < 5.11.3 - SQL Injection POC
SQL injection vulnerability in Nagios XI before version 5.11.3 via the bulk modification tool. -
nagios-default-login: Nagios Default Login POC
Nagios default admin credentials were discovered. -
nagiosxi-default-login: Nagios XI Default Admin Login - Detect POC
Nagios XI default admin login credentials were detected. -
nagios-status-page: Nagios Current Status Page - Detect POC
Nagios current status page was detected. -
nagios-logserver-installer: Nagios Log Server - Install POC
Detects the presence of a Nagios Log Server installation page, which can expose configuration setup information or initialization steps. -
nagiosxi-installer: Nagios XI Installer POC
Nagios XI is susceptible to the Installation page exposure due to misconfiguration. -
nagios-xi-xss: Nagios XI 5.7.1 - Cross-Site Scripting POC
A reflected cross-site scripting (XSS) in Nagios XI 5.7.1 can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. -
Nagios XI banner_message-ajaxhelper.php SQL注入漏洞 无POC
Nagios XI是一个流行的和广泛使用的商业监控解决方案,用于IT基础设施和网络监控,Nagios XI存在sql注入漏洞,此漏洞是由于banner_message-ajaxhelper.php接口对用户的请求验证不当导致的。 -
Nagios XI CVE-2023-40934 SQL注入漏洞 无POC
Nagios XI是一款商业版本的企业服务器和网络监控软件。Nagios XI存在sql注入漏洞,该漏洞是由于ccm接口对用户的请求验证不当导致的。 -
Nagios Network Analyzer SQL 注入漏洞(CVE-2021-28925) 无POC
Nagios Network Analyzer 2.4.3 之前的版本中存在 SQL 注入漏洞,参数为 o[col],接口为 api/checks/read/。 -
Nagios XI CVE-2023-48085 远程代码执行漏洞 无POC
Nagios XI是一套IT基础设施监控解决方案。Nagios XI存在远程代码执行漏洞,此漏洞是由于command_test.php接口对用户的请求验证不当导致的。