Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pnp4nagios pnp4nagios vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv2
CVE-2017-16834
PNP4Nagios up to and including 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.
Pnp4nagios Pnp4nagios
4.3
CVSSv2
CVE-2014-4907
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios prior to 0.6.22 allows remote malicious users to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.
Op5 Monitor 6.3.0
Pnp4nagios Pnp4nagios 0.6.1
Pnp4nagios Pnp4nagios 0.6.10
Pnp4nagios Pnp4nagios 0.6.17
Pnp4nagios Pnp4nagios 0.6.18
Pnp4nagios Pnp4nagios 0.6.19
Pnp4nagios Pnp4nagios 0.6.0
Pnp4nagios Pnp4nagios 0.6.15
Pnp4nagios Pnp4nagios 0.6.16
Pnp4nagios Pnp4nagios 0.6.7
Pnp4nagios Pnp4nagios 0.6.11
Pnp4nagios Pnp4nagios 0.6.12
Pnp4nagios Pnp4nagios 0.6.2
Pnp4nagios Pnp4nagios 0.6.3
Pnp4nagios Pnp4nagios 0.6.4
Pnp4nagios Pnp4nagios
Pnp4nagios Pnp4nagios 0.6.20
Pnp4nagios Pnp4nagios 0.6.13
Pnp4nagios Pnp4nagios 0.6.14
Pnp4nagios Pnp4nagios 0.6.5
Pnp4nagios Pnp4nagios 0.6.6
4.3
CVSSv2
CVE-2014-4908
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios up to and including 0.6.22 allow remote malicious users to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/...
Pnp4nagios Pnp4nagios 0.6.20
Pnp4nagios Pnp4nagios 0.6.11
Pnp4nagios Pnp4nagios 0.6.13
Pnp4nagios Pnp4nagios 0.6.3
Pnp4nagios Pnp4nagios 0.6.5
Pnp4nagios Pnp4nagios 0.6.19
Pnp4nagios Pnp4nagios 0.6.0
Pnp4nagios Pnp4nagios 0.6.1
Pnp4nagios Pnp4nagios 0.6.10
Pnp4nagios Pnp4nagios 0.6.6
Pnp4nagios Pnp4nagios 0.6.7
Pnp4nagios Pnp4nagios 0.6.15
Pnp4nagios Pnp4nagios 0.6.16
Pnp4nagios Pnp4nagios 0.6.17
Pnp4nagios Pnp4nagios 0.6.18
Pnp4nagios Pnp4nagios
Pnp4nagios Pnp4nagios 0.6.12
Pnp4nagios Pnp4nagios 0.6.14
Pnp4nagios Pnp4nagios 0.6.2
Pnp4nagios Pnp4nagios 0.6.4
2.1
CVSSv2
CVE-2012-3457
PNP4Nagios 0.6 up to and including 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file.
Pnp4nagios Pnp4nagios 0.6.7
Pnp4nagios Pnp4nagios 0.6.10
Pnp4nagios Pnp4nagios 0.6.0
Pnp4nagios Pnp4nagios 0.6.1
Pnp4nagios Pnp4nagios 0.6.11
Pnp4nagios Pnp4nagios 0.6.5
Pnp4nagios Pnp4nagios 0.6.6
Pnp4nagios Pnp4nagios 0.6.15
Pnp4nagios Pnp4nagios 0.6.16
Pnp4nagios Pnp4nagios 0.6.12
Pnp4nagios Pnp4nagios 0.6.2
Pnp4nagios Pnp4nagios 0.6.3
Pnp4nagios Pnp4nagios 0.6.4
Pnp4nagios Pnp4nagios 0.6.13
Pnp4nagios Pnp4nagios 0.6.14
NA
CVE-2023-38349
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
Pnp4nagios Pnp4nagios 0.6.26
NA
CVE-2023-38350
PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.
Pnp4nagios Pnp4nagios 0.6.26
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started