CVE-2008-5028
Summary
| CVE | CVE-2008-5028 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-10 15:23:29 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nagios | Nagios | 1.0 | All | All | All |
| Application | Nagios | Nagios | 1.0b1 | All | All | All |
| Application | Nagios | Nagios | 1.0b2 | All | All | All |
| Application | Nagios | Nagios | 1.0b3 | All | All | All |
| Application | Nagios | Nagios | 1.0b4 | All | All | All |
| Application | Nagios | Nagios | 1.0b5 | All | All | All |
| Application | Nagios | Nagios | 1.0b6 | All | All | All |
| Application | Nagios | Nagios | 1.0_b1 | All | All | All |
| Application | Nagios | Nagios | 1.0_b2 | All | All | All |
| Application | Nagios | Nagios | 1.0_b3 | All | All | All |
| Application | Nagios | Nagios | 1.1 | All | All | All |
| Application | Nagios | Nagios | 1.2 | All | All | All |
| Application | Nagios | Nagios | 1.3 | All | All | All |
| Application | Nagios | Nagios | 1.4 | All | All | All |
| Application | Nagios | Nagios | 1.4.1 | All | All | All |
| Application | Nagios | Nagios | 2.0 | All | All | All |
| Application | Nagios | Nagios | 2.0b1 | All | All | All |
| Application | Nagios | Nagios | 2.0b2 | All | All | All |
| Application | Nagios | Nagios | 2.0b3 | All | All | All |
| Application | Nagios | Nagios | 2.0b4 | All | All | All |
| Application | Nagios | Nagios | 2.0b5 | All | All | All |
| Application | Nagios | Nagios | 2.0b6 | All | All | All |
| Application | Nagios | Nagios | 2.0rc1 | All | All | All |
| Application | Nagios | Nagios | 2.0rc2 | All | All | All |
| Application | Nagios | Nagios | 2.1 | All | All | All |
| Application | Nagios | Nagios | 2.10 | All | All | All |
| Application | Nagios | Nagios | 2.11 | All | All | All |
| Application | Nagios | Nagios | 2.2 | All | All | All |
| Application | Nagios | Nagios | 2.3 | All | All | All |
| Application | Nagios | Nagios | 2.3.1 | All | All | All |
| Application | Nagios | Nagios | 2.4 | All | All | All |
| Application | Nagios | Nagios | 2.5 | All | All | All |
| Application | Nagios | Nagios | 2.7 | All | All | All |
| Application | Nagios | Nagios | 2.8 | All | All | All |
| Application | Nagios | Nagios | 2.9 | All | All | All |
| Application | Nagios | Nagios | 3.0 | All | All | All |
| Application | Nagios | Nagios | 3.0 | alpha1 | All | All |
| Application | Nagios | Nagios | 3.0 | alpha2 | All | All |
| Application | Nagios | Nagios | 3.0 | alpha3 | All | All |
| Application | Nagios | Nagios | 3.0 | alpha4 | All | All |
| Application | Nagios | Nagios | 3.0 | beta1 | All | All |
| Application | Nagios | Nagios | 3.0 | beta2 | All | All |
| Application | Nagios | Nagios | 3.0 | beta3 | All | All |
| Application | Nagios | Nagios | 3.0 | beta4 | All | All |
| Application | Nagios | Nagios | 3.0 | beta5 | All | All |
| Application | Nagios | Nagios | 3.0 | beta6 | All | All |
| Application | Nagios | Nagios | 3.0 | beta7 | All | All |
| Application | Nagios | Nagios | 3.0 | rc1 | All | All |
| Application | Nagios | Nagios | 3.0 | rc2 | All | All |
| Application | Nagios | Nagios | 3.0 | rc3 | All | All |
| Application | Nagios | Nagios | 3.0.1 | All | All | All |
| Application | Nagios | Nagios | 3.0.2 | All | All | All |
| Application | Nagios | Nagios | 3.0.3 | All | All | All |
| Application | Nagios | Nagios | All | All | All | All |
| Application | Op5 | Monitor | 2.4 | All | All | All |
| Application | Op5 | Monitor | 2.6 | All | All | All |
| Application | Op5 | Monitor | 2.8 | All | All | All |
| Application | Op5 | Monitor | 3.0 | All | All | All |
| Application | Op5 | Monitor | 3.0.0 | All | All | All |
| Application | Op5 | Monitor | 3.2 | All | All | All |
| Application | Op5 | Monitor | 3.2.4 | All | All | All |
| Application | Op5 | Monitor | 3.3.1 | All | All | All |
| Application | Op5 | Monitor | 3.3.2 | All | All | All |
| Application | Op5 | Monitor | 3.3.3 | All | All | All |
| Application | Op5 | Monitor | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ubuntu update for nagios2 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Important security fix available for op5 Monitor | af854a3a-2127-422b-91ae-364da2661108 | www.op5.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Nagios "cmd.cgi" Cross-Site Request Forgery - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| op5 Monitor Cross-Site Request Forgery - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/49678 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| HP Insight Control Suite For Linux Nagios Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| oss-security - CVE request: Nagios (two issues) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| git.op5.org/git | af854a3a-2127-422b-91ae-364da2661108 | git.op5.org | |
| USN-698-3: Nagios vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| SourceForge.net: Nagios: nagios-devel | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| HP Insight Control suite for Linux Bugs in Nagios Let Remote Users Conduct Cross-Site Request Forgery Attacks and Bypass Authentication - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Gentoo Linux Documentation -- Nagios: Execution of arbitrary code | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| op5.org | MITRE | git.op5.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.