CVE-2020-27990
https://notcve.org/view.php?id=CVE-2020-27990
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent). Nagios XI versiones anteriores a 5.7.5, es vulnerable a un ataque de tipo XSS en la herramienta Deployment (add agent) • https://www.nagios.com/downloads/nagios-xi/change-log • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-27989
https://notcve.org/view.php?id=CVE-2020-27989
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard). Nagios XI versiones anteriores a 5.7.5, es vulnerable a un ataque de tipo XSS en Dashboard Tools (Panel Edit) • https://www.nagios.com/downloads/nagios-xi/change-log • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-27988
https://notcve.org/view.php?id=CVE-2020-27988
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field). Nagios XI versiones anteriores a 5.7.5, es vulnerable a un ataque de tipo XSS en Manage Users (campo Username) • https://www.nagios.com/downloads/nagios-xi/change-log • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-28648 – Nagios XI / Fusion Privilege Escalation / Cross Site Scripting / Code Execution
https://notcve.org/view.php?id=CVE-2020-28648
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code. Una comprobación inapropiada de entrada en el componente Auto-Discovery de Nagios XI versiones anteriores a 5.7.5, permite a un atacante autenticado ejecutar código remoto Skylight Cyber has identified a total of 13 vulnerabilities in Nagios XI and Nagios Fusion servers. These include remote code execution, cross site scripting, privilege escalation, and more. • http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you https://www.nagios.com/downloads/nagios-xi/change-log • CWE-20: Improper Input Validation •
CVE-2020-5796
https://notcve.org/view.php?id=CVE-2020-5796
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privileges. Una conservación inapropiada de permisos en Nagios XI versión 5.7.4, permite a un usuario autenticado local, poco privilegiado, debilitar unos permisos de archivos, resultando en que usuarios poco privilegiados poder ser capaces de escribir y ejecutar código PHP arbitrario con privilegios root • https://www.tenable.com/security/research/tra-2020-61 • CWE-281: Improper Preservation of Permissions •