PT-2013-4439 · Groundwork · Groundwork Monitor Enterprise
Published
2013-05-08
·
Updated
2013-05-08
·
CVE-2013-3504
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GroundWork Monitor Enterprise version 6.7.0
Description
A directory traversal issue exists in the monarch.cgi component of GroundWork Monitor Enterprise, allowing remote authenticated users with access to the nagios account to overwrite arbitrary files.
Recommendations
For GroundWork Monitor Enterprise version 6.7.0, consider restricting access to the monarch.cgi component until a patch is available. As a temporary workaround, limit the privileges of the nagios account to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Groundwork Monitor Enterprise