Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-25299 PoC — Nagios XI和Nagios 跨站脚本漏洞

Source
Associated Vulnerability
Title:Nagios XI和Nagios 跨站脚本漏洞 (CVE-2021-25299)
Description:Nagios XI和Nagios都是美国Nagios公司的产品。Nagios XI是一套IT基础设施监控解决方案。该方案支持对应用、服务、操作系统等进行监控和预警。Nagios是一套开源的免费网络监视工具。 NagiosXI中存在跨站脚本漏洞,该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Description
Nagios XI 5.7.5 contains a cross-site scripting vulnerability in the file /usr/local/nagiosxi/html/admin/sshterm.php, due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal session cookies, or it can be chained with the previous bugs to get one-click remote command execution on the Nagios XI server.
File Snapshot

id: CVE-2021-25299 info: name: Nagios XI 5.7.5 - Cross-Site Scripting author: ritikchaddha se ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.