Nagios XI CVE-2018-15708 Command Injection Vulnerability
BID:108895
Info
Nagios XI CVE-2018-15708 Command Injection Vulnerability
| Bugtraq ID: | 108895 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-15708 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2018 12:00AM |
| Updated: | Nov 14 2018 12:00AM |
| Credit: | Chris Lyne |
| Vulnerable: |
Nagios Nagios XI 5.5.6 |
| Not Vulnerable: |
Nagios Nagios XI 5.5.7 |
Discussion
Nagios XI CVE-2018-15708 Command Injection Vulnerability
Nagios XI is prone to a command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in the context of the affected application.
Nagios XI 5.5.6 is vulnerable; other versions may also be affected.
Nagios XI is prone to a command-injection vulnerability.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in the context of the affected application.
Nagios XI 5.5.6 is vulnerable; other versions may also be affected.
Exploit / POC
Nagios XI CVE-2018-15708 Command Injection Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Nagios XI CVE-2018-15708 Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Nagios XI CVE-2018-15708 Command Injection Vulnerability
References:
References:
- Nagios Homepage (Nagios)
- Security Vulnerability: Upgrade to Nagios XI 5.5.7 (Nagios XI)
- [R2] Nagios XI Multiple Vulnerabilities (Tenable)