Total
90 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-25297 | 1 Nagios | 1 Nagios Xi | 2023-02-28 | 9.0 HIGH | 8.8 HIGH |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server. | |||||
CVE-2021-25296 | 1 Nagios | 1 Nagios Xi | 2023-02-28 | 9.0 HIGH | 8.8 HIGH |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server. | |||||
CVE-2021-25298 | 1 Nagios | 1 Nagios Xi | 2023-02-28 | 9.0 HIGH | 8.8 HIGH |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server. | |||||
CVE-2020-5791 | 1 Nagios | 1 Nagios Xi | 2023-01-24 | 9.0 HIGH | 7.2 HIGH |
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user. | |||||
CVE-2020-15901 | 1 Nagios | 1 Nagios Xi | 2022-12-03 | 7.5 HIGH | 8.8 HIGH |
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys. | |||||
CVE-2021-40345 | 1 Nagios | 1 Nagios Xi | 2022-11-07 | 9.0 HIGH | 7.2 HIGH |
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands. | |||||
CVE-2020-28648 | 1 Nagios | 1 Nagios Xi | 2022-10-18 | 9.0 HIGH | 8.8 HIGH |
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code. | |||||
CVE-2019-9167 | 1 Nagios | 1 Nagios Xi | 2022-10-06 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter. | |||||
CVE-2019-9166 | 1 Nagios | 1 Nagios Xi | 2022-10-06 | 7.2 HIGH | 7.8 HIGH |
Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php. | |||||
CVE-2019-9165 | 1 Nagios | 1 Nagios Xi | 2022-10-06 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id. | |||||
CVE-2019-9164 | 1 Nagios | 1 Nagios Xi | 2022-10-06 | 6.5 MEDIUM | 8.8 HIGH |
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job. | |||||
CVE-2022-38248 | 1 Nagios | 1 Nagios Xi | 2022-09-09 | N/A | 6.1 MEDIUM |
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php. | |||||
CVE-2022-38247 | 1 Nagios | 1 Nagios Xi | 2022-09-09 | N/A | 4.8 MEDIUM |
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel. | |||||
CVE-2022-38249 | 1 Nagios | 1 Nagios Xi | 2022-09-09 | N/A | 6.1 MEDIUM |
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4. | |||||
CVE-2022-38250 | 1 Nagios | 1 Nagios Xi | 2022-09-09 | N/A | 9.8 CRITICAL |
Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page. | |||||
CVE-2022-38251 | 1 Nagios | 1 Nagios Xi | 2022-09-09 | N/A | 4.8 MEDIUM |
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel. | |||||
CVE-2022-38254 | 1 Nagios | 1 Nagios Xi | 2022-09-09 | N/A | 6.1 MEDIUM |
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5. | |||||
CVE-2021-37347 | 1 Nagios | 1 Nagios Xi | 2022-07-12 | 4.6 MEDIUM | 7.8 HIGH |
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument. | |||||
CVE-2020-28910 | 1 Nagios | 1 Nagios Xi | 2022-07-12 | 10.0 HIGH | 9.8 CRITICAL |
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh. | |||||
CVE-2021-37349 | 1 Nagios | 1 Nagios Xi | 2022-07-12 | 4.6 MEDIUM | 7.8 HIGH |
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database. |