Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Nagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nagios插件SHELL字符远程任意命令执行漏洞
Vulnerability Description
Nagios是美国程序员Ethan Galstad所研发的一套开源的系统运行状态和网络信息监控程序。该程序提供网络服务监控、主机资源监控、短信报警等功能。 Nagios服务程序对插件发送的恶意数据缺少正确的过滤,远程攻击者可以利用这个漏洞在系统上以Nagios进程的权限在系统上执行任意命令。 攻击者可以产生一事件引起插件发送恶意格式的数据给Nagios服务器,由于Nagios服务程序对包含的数据缺少正确的过滤,如果数据中包含元字符和任意命令,当接收解析这个数据时,包含在元字符之间的任意命令将以Nagios
CVSS Information
N/A
Vulnerability Type
N/A