Nagios XI 漏洞列表
共找到 19 个与 Nagios XI 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2021-25296: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25298: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25299: Nagios XI 5.7.5 - Cross-Site Scripting POC
Nagios XI 5.7.5 contains a cross-site scripting vulnerability in the file /usr/local/nagiosxi/html/admin/sshterm.php, due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal session cookies, or it can be chained with the previous bugs to get one-click remote command execution on the Nagios XI server. -
CVE-2021-38156: Nagios XI < 5.8.6 - Cross-Site Scripting POC
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard. -
CVE-2022-29272: Nagios XI <5.8.5 - Open Redirect POC
Nagios XI through 5.8.5 contains an open redirect vulnerability in the login function. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. -
CVE-2023-40931: Nagios XI v5.11.0 - SQL Injection POC
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php. -
CVE-2023-48084: Nagios XI < 5.11.3 - SQL Injection POC
SQL injection vulnerability in Nagios XI before version 5.11.3 via the bulk modification tool. -
CVE-2021-25296: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25298: Nagios XI 5.5.6-5.7.5 - Authenticated Remote Command Injection POC
Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. -
CVE-2021-25299: Nagios XI 5.7.5 - Cross-Site Scripting POC
Nagios XI 5.7.5 contains a cross-site scripting vulnerability in the file /usr/local/nagiosxi/html/admin/sshterm.php, due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal session cookies, or it can be chained with the previous bugs to get one-click remote command execution on the Nagios XI server. -
CVE-2021-38156: Nagios XI < 5.8.6 - Cross-Site Scripting POC
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard. -
CVE-2022-29272: Nagios XI <5.8.5 - Open Redirect POC
Nagios XI through 5.8.5 contains an open redirect vulnerability in the login function. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. -
CVE-2023-40931: Nagios XI v5.11.0 - SQL Injection POC
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php. -
CVE-2023-48084: Nagios XI < 5.11.3 - SQL Injection POC
SQL injection vulnerability in Nagios XI before version 5.11.3 via the bulk modification tool. -
nagiosxi-default-login: Nagios XI Default Admin Login - Detect POC
Nagios XI default admin login credentials were detected. -
nagios-xi-xss: Nagios XI 5.7.1 - Cross-Site Scripting POC
A reflected cross-site scripting (XSS) in Nagios XI 5.7.1 can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. -
Nagios XI banner_message-ajaxhelper.php SQL注入漏洞 无POC
Nagios XI是一个流行的和广泛使用的商业监控解决方案,用于IT基础设施和网络监控,Nagios XI存在sql注入漏洞,此漏洞是由于banner_message-ajaxhelper.php接口对用户的请求验证不当导致的。 -
Nagios XI CVE-2023-40934 SQL注入漏洞 无POC
Nagios XI是一款商业版本的企业服务器和网络监控软件。Nagios XI存在sql注入漏洞,该漏洞是由于ccm接口对用户的请求验证不当导致的。 -
Nagios XI CVE-2023-48085 远程代码执行漏洞 无POC
Nagios XI是一套IT基础设施监控解决方案。Nagios XI存在远程代码执行漏洞,此漏洞是由于command_test.php接口对用户的请求验证不当导致的。