PT-2019-16122 · Nagios · Nagios Xi

Code16

·

Publicado

2019-12-31

·

Atualizado

2020-01-07

·

CVE-2019-20197

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios XI version 5.6.9
Description The issue allows an authenticated user to execute arbitrary OS commands via shell metacharacters in the id parameter to "schedulereport.php", in the context of the web-server user account.
Recommendations For Nagios XI version 5.6.9, avoid using the id parameter in the "schedulereport.php" endpoint until the issue is resolved. Consider restricting access to the schedulereport.php endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-20197

Produtos afetados

Nagios Xi