Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nagios xi vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2020-10819
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.
Nagios Nagios Xi 5.6.11
3.5
CVSSv2
CVE-2020-10820
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.
Nagios Nagios Xi 5.6.11
3.5
CVSSv2
CVE-2020-10821
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
Nagios Nagios Xi 5.6.11
9
CVSSv2
CVE-2019-20197
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
Nagios Nagios Xi 5.6.9
2 Github repositories
3.5
CVSSv2
CVE-2019-20139
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
Nagios Nagios Xi 5.6.9
9
CVSSv2
CVE-2019-15949
Nagios XI prior to 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is exec...
Nagios Nagios Xi
1 EDB exploit
4 Github repositories
3.5
CVSSv2
CVE-2018-17147
Nagios XI prior to 5.5.4 has XSS in the auto login admin management page.
Nagios Nagios Xi
3.5
CVSSv2
CVE-2018-17146
A cross-site scripting vulnerability exists in Nagios XI prior to 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an malicious user to execute arbitrary JavaScript code within the auto login admin management ...
Nagios Nagios Xi
5
CVSSv2
CVE-2018-17148
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI prior to 5.5.4 allows remote malicious users to gain access to configuration files containing confidential credentials.
Nagios Nagios Xi
7.5
CVSSv2
CVE-2019-12279
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any va...
Nagios Nagios Xi 5.6.1
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-3611
CVE-2024-4947
CVE-2024-32988
CVE-2020-35165
local file inclusion
CVE-2024-4980
bypass
malicious code
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »