RSS   Vulnerabilities for 'Nagios xi'   RSS

2018-12-17
 
CVE-2018-20172

CWE-79
 

 
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.

 
 
CVE-2018-20171

CWE-79
 

 
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.

 
2018-11-14
 
CVE-2018-15714

CWE-79
 

 
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.

 
 
CVE-2018-15713

CWE-79
 

 
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.

 
 
CVE-2018-15712

CWE-79
 

 
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.

 
 
CVE-2018-15711

CWE-264
 

 
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.

 
 
CVE-2018-15710

CWE-77
 

 
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.

 
 
CVE-2018-15709

CWE-77
 

 
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.

 
 
CVE-2018-15708

CWE-77
 

 
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.

 
2018-05-16
 
CVE-2018-10738

CWE-89
 

 
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.

 


Copyright 2019, cxsecurity.com

 

Back to Top