PT-2019-16122 · Nagios · Nagios Xi

Code16

·

Published

2019-12-31

·

Updated

2020-01-07

·

CVE-2019-20197

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios XI version 5.6.9
Description The issue allows an authenticated user to execute arbitrary OS commands via shell metacharacters in the id parameter to "schedulereport.php", in the context of the web-server user account.
Recommendations For Nagios XI version 5.6.9, avoid using the id parameter in the "schedulereport.php" endpoint until the issue is resolved. Consider restricting access to the schedulereport.php endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20197

Affected Products

Nagios Xi