CVE-2018-16146
Summary
| CVE | CVE-2018-16146 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-05 21:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifications that are triggered under certain configurable events. The value parameter is not properly sanitized, leading to arbitrary command injection with the privileges of the nagios user account. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: [CORE-2018-0008] - Opsview Monitor Multiple Vulnerabilities | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Opsview Monitor Multiple Vulnerabilities | SecureAuth | MISC | www.coresecurity.com | Exploit, Third Party Advisory |
| What's New? | CONFIRM | knowledge.opsview.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.