Nagios XI 'visApi.php' Multiple Command Injection Vulnerabilities
BID:54263
Info
Nagios XI 'visApi.php' Multiple Command Injection Vulnerabilities
| Bugtraq ID: | 54263 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2012 12:00AM |
| Updated: | Dec 10 2012 02:40PM |
| Credit: | Daniel Compton of NCC Group |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Nagios XI 'visApi.php' Multiple Command Injection Vulnerabilities
Nagios XI is prone to multiple command-injection vulnerabilities because it fails to adequately sanitize user-supplied input.
Attackers can exploit these issues to execute arbitrary commands in the context of the web server process. Successful exploits could compromise the application and possibly the underlying system.
Nagios XI Network Monitor 2011R1.9, Nagios XI Graph Explorer component versions prior to 1.3 are vulnerable.
Nagios XI is prone to multiple command-injection vulnerabilities because it fails to adequately sanitize user-supplied input.
Attackers can exploit these issues to execute arbitrary commands in the context of the web server process. Successful exploits could compromise the application and possibly the underlying system.
Nagios XI Network Monitor 2011R1.9, Nagios XI Graph Explorer component versions prior to 1.3 are vulnerable.
Exploit / POC
Nagios XI 'visApi.php' Multiple Command Injection Vulnerabilities
An attacker can exploit the issue through a browser.
The following exploit is available:
An attacker can exploit the issue through a browser.
The following exploit is available:
Solution / Fix
Nagios XI 'visApi.php' Multiple Command Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Nagios XI 'visApi.php' Multiple Command Injection Vulnerabilities
References:
References:
- Nagios XI Homepage (Nagios)