This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:nagios:nagios:2.3.1 |
| Detail | |||
|---|---|---|---|
| Vendor | Nagios | First view | 2008-03-17 |
| Product | Nagios | Last view | 2011-05-03 |
| Version | 2.3.1 | Type | Application |
| Edition | |||
| Language | |||
| Update | |||
| CPE Product | cpe:/a:nagios:nagios | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4.3 | 2011-05-03 | CVE-2011-1523 | Network | Medium | None Requ... | |
| 5 | 2009-03-02 | CVE-2008-6373 | Network | Low | None Requ... | |
| 6.8 | 2008-11-10 | CVE-2008-5028 | Network | Medium | None Requ... | |
| 6.5 | 2008-11-10 | CVE-2008-5027 | Network | Low | Requires ... | |
| 4.3 | 2008-05-13 | CVE-2007-5803 | Network | Medium | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4.3 | 2008-03-17 | CVE-2008-1360 | Network | Medium | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 50% (3) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| 16% (1) | CWE-352 | Cross-Site Request Forgery (CSRF) |
| 16% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
| 16% (1) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
CAPEC : Common Attack Pattern Enumeration & Classificatio
| id | Name |
|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
| CAPEC-13 | Subverting Environment Variable Values |
| CAPEC-17 | Accessing, Modifying or Executing Executable Files |
| CAPEC-39 | Manipulating Opaque Client-based Data Tokens |
| CAPEC-45 | Buffer Overflow via Symbolic Links |
| id | Name |
|---|---|
| CAPEC-51 | Poison Web Service Registry |
| CAPEC-59 | Session Credential Falsification through Prediction |
| CAPEC-60 | Reusing Session IDs (aka Session Replay) |
| CAPEC-76 | Manipulating Input to File System Calls |
| CAPEC-77 | Manipulating User-Controlled Variables |
| CAPEC-87 | Forceful Browsing |
| CAPEC-104 | Cross Zone Scripting |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 71059 | Nagios cgi-bin/statusmap.cgi layer Parameter XSS |
| 50457 | Nagios Unspecified CGI Issue |
| 50242 | op5 Nagios Process Browser Addon Remote Authentication Bypass |
| 50241 | op5 Nagios Process Custom Form Remote Authentication Bypass |
| 50240 | Nagios Nagios Process Browser Addon Remote Authentication Bypass |
| id | Description |
|---|---|
| 50239 | Nagios Nagios Process Custom Form Remote Authentication Bypass |
| 49994 | op5 Monitor Unspecified CSRF |
| 49991 | Nagios Unspecified CSRF |
| 45359 | Nagios Unspecified CGI XSS |
| 42951 | Nagios Unspecified XSS |









