Vulnerabilities
Vulnerable Software
Nagios:  Security Vulnerabilities
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.
CVSS Score
9.8
EPSS Score
0.097
Published
2019-03-28
Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.
CVSS Score
8.8
EPSS Score
0.613
Published
2019-03-28
Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.
CVSS Score
9.8
EPSS Score
0.02
Published
2019-03-28
SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.
CVSS Score
9.8
EPSS Score
0.197
Published
2019-03-28
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
CVSS Score
8.8
EPSS Score
0.365
Published
2019-03-28
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
CVSS Score
6.1
EPSS Score
0.038
Published
2018-12-17
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
CVSS Score
6.1
EPSS Score
0.038
Published
2018-12-17
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
CVSS Score
5.4
EPSS Score
0.056
Published
2018-12-17
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
CVSS Score
9.8
EPSS Score
0.92
Published
2018-11-14
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
CVSS Score
8.8
EPSS Score
0.112
Published
2018-11-14


Contact Us

Shodan ® - All rights reserved