Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icinga icinga web 2 vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2018-18247
Icinga Web 2 prior to 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
Icinga Icinga Web 2
9.8
CVSSv3
CVE-2018-18249
Icinga Web 2 prior to 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or /icingawe...
Icinga Icinga Web 2
8.8
CVSSv3
CVE-2022-24715
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved ...
Icinga Icinga Web 2
1 EDB exploit
2 Github repositories
7.5
CVSSv3
CVE-2022-24716
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This is...
Icinga Icinga Web 2
5 Github repositories
6.5
CVSSv3
CVE-2018-18246
Icinga Web 2 prior to 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.
Icinga Icinga Web 2
7.5
CVSSv3
CVE-2018-18250
Icinga Web 2 prior to 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item.
Icinga Icinga Web 2
5.3
CVSSv3
CVE-2022-24714
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with ...
Icinga Icinga Web 2
6.1
CVSSv3
CVE-2018-18248
Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.
Icinga Icinga Web 2 2.6.1
7.5
CVSSv3
CVE-2020-24368
Icinga Icinga Web2 2.0.0 up to and including 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an malicious user to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2...
Icinga Icinga Web 2
Debian Debian Linux 9.0
Debian Debian Linux 10
Suse Package Hub -
NA
CVE-2011-2179
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga prior to 1.4.1 allow remote malicious users to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts ac...
Icinga Icinga 1.3.1
Icinga Icinga 1.0.2
Icinga Icinga 0.8.1
Icinga Icinga 0.8.0
Icinga Icinga
Icinga Icinga 1.3.0
Icinga Icinga 1.0.1
Icinga Icinga 1.0
Nagios Nagios 3.2.3
Icinga Icinga 0.8.4
Icinga Icinga 1.0.3
Icinga Icinga 1.2.0
Icinga Icinga 1.2.1
Icinga Icinga 0.8.3
Icinga Icinga 0.8.2
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4761
command injection
CVE-2024-3676
IDOR
CVE-2024-30039
CVE-2024-32113
CVE-2024-30049
CVE-2024-4776
SQL injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »