Nagios XI是美国Nagios公司的一套IT基础设施监控解决方案。该方案支持对应用、服务、操作系统等进行监控和预警。 Nagios XI 5.7.5中存在安全漏洞,该漏洞源于外部输入数据构造可执行命令过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞执行非法命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Nagios XI 5.5.6 through 5.7.5 is susceptible to authenticated remote command injection. There is improper sanitization of authenticated user-controlled input by a single HTTP request via the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php. This in turn can lead to remote code execution, by which an attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-25298.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-23337 | 7.2 HIGH | Command Injection |
| CVE-2021-23338 | 6.6 MEDIUM | Deserialization of Untrusted Data |
| CVE-2021-23336 | 5.9 MEDIUM | Web Cache Poisoning |
| CVE-2020-28500 | 5.3 MEDIUM | Regular Expression Denial of Service (ReDoS) |
| CVE-2020-24899 | Nagios XI和Nagios 命令注入漏洞 | |
| CVE-2021-26822 | Teachers Record Management System SQL注入漏洞 | |
| CVE-2020-35734 | Batflat 注入漏洞 | |
| CVE-2021-26201 | CASAP Automated Enrollment SQL注入漏洞 | |
| CVE-2021-26200 | SourceCodester user area for Library System SQL注入漏洞 | |
| CVE-2021-3239 | Sourcecodester Pisay Online E-Learning System SQL注入漏洞 | |
| CVE-2020-29143 | OpenEMR SQL注入漏洞 | |
| CVE-2020-29139 | OpenEMR SQL注入漏洞 | |
| CVE-2020-29140 | OpenEMR SQL注入漏洞 | |
| CVE-2020-29142 | OpenEMR SQL注入漏洞 | |
| CVE-2020-28337 | Microweber 路径遍历漏洞 | |
| CVE-2021-27211 | Steghide 安全漏洞 | |
| CVE-2021-27201 | Endian Firewall Community 操作系统命令注入漏洞 | |
| CVE-2021-3375 | Atomi ActivePresenter 缓冲区错误漏洞 | |
| CVE-2021-25296 | Nagios XI 安全漏洞 | |
| CVE-2020-22427 | Nagios XI 代码注入漏洞 |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet