Page 8 of 44 results (0.008 seconds)

CVSS: 5.4EPSS: 3%CPEs: 1EXPL: 0

Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent). Nagios XI versiones anteriores a 5.7.5, es vulnerable a un ataque de tipo XSS en la herramienta Deployment (add agent) • https://www.nagios.com/downloads/nagios-xi/change-log • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 3%CPEs: 1EXPL: 0

Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard). Nagios XI versiones anteriores a 5.7.5, es vulnerable a un ataque de tipo XSS en Dashboard Tools (Panel Edit) • https://www.nagios.com/downloads/nagios-xi/change-log • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 3%CPEs: 1EXPL: 0

Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field). Nagios XI versiones anteriores a 5.7.5, es vulnerable a un ataque de tipo XSS en Manage Users (campo Username) • https://www.nagios.com/downloads/nagios-xi/change-log • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.0EPSS: 14%CPEs: 1EXPL: 2

Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code. Una comprobación inapropiada de entrada en el componente Auto-Discovery de Nagios XI versiones anteriores a 5.7.5, permite a un atacante autenticado ejecutar código remoto Skylight Cyber has identified a total of 13 vulnerabilities in Nagios XI and Nagios Fusion servers. These include remote code execution, cross site scripting, privilege escalation, and more. • http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you https://www.nagios.com/downloads/nagios-xi/change-log • CWE-20: Improper Input Validation •

CVSS: 9.0EPSS: 84%CPEs: 1EXPL: 4

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user. Una neutralización inapropiada de elementos especiales utilizados en un comando del Sistema Operativo en Nagios XI versión 5.7.3, permite a un usuario administrador autenticado remoto ejecutar comandos del sistema operativo con los privilegios del usuario de apache • https://www.exploit-db.com/exploits/48959 http://packetstormsecurity.com/files/159743/Nagios-XI-5.7.3-Remote-Command-Injection.html http://packetstormsecurity.com/files/162235/Nagios-XI-5.7.3-Remote-Code-Execution.html https://www.tenable.com/security/research/tra-2020-58 - • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •