Nagios XI OS Command Injection Vulnerability
ID: 0a827bbb-10e3-50ed-98e4-94a48055eb60
STIX ID: report--0a827bbb-10e3-50ed-98e4-94a48055eb60
Feed Name: NCC Research
Threat Score
Nagios XI Network Monitor 2011R1.9 contains an authenticated OS command injection in the Graph Explorer component (visApi.php) via GET parameters (host, service, opt, end, start); a proof-of-concept demonstrates it can read /etc/passwd. The flaw was reported by Daniel Compton and resolved in Graph Explorer SVN 1.3 (05/23/2012).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
