Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NRPE ‘nrpc.c’ 任意代码执行漏洞
Vulnerability Description
Nagios是美国程序员Ethan Galstad所研发的一套开源的系统运行状态和网络信息监控程序。Nagios Remote Plugin Executor(NRPE)是一个Nagios代理,它用在被监控的服务器上,向Nagios监控平台提供该服务器的一些本地情况。 NRPE中的nrpc.c中存在远程任意代码执行漏洞,该漏洞源于程序没有正确验证用户提供的输入。攻击者利用该漏洞在受影响应用程序上下文中执行任意命令。NRPE 2.13版本中存在漏洞,其他版本也可能受到影响。
CVSS Information
N/A
Vulnerability Type
N/A