This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Nagios First view 2013-11-26
Product Nagios Xi Last view 2022-09-07
Version 5.5.6 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:nagios:nagios_xi

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
6.1 2022-09-07 CVE-2022-38254

Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.

6.1 2022-09-07 CVE-2022-38248

Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

6.1 2022-06-29 CVE-2022-29272

In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

6.5 2022-06-29 CVE-2022-29271

In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.

4.3 2022-06-29 CVE-2022-29270

In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.

6.5 2022-06-29 CVE-2022-29269

In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.

6.1 2021-10-14 CVE-2021-33179

The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.

8.8 2021-10-14 CVE-2021-33177

The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.

6.5 2021-10-05 CVE-2021-37223

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the target page can be replaced with an SSRF payload to access internal resources or disclose local system files.

9.8 2021-09-28 CVE-2021-36366

Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

9.8 2021-09-28 CVE-2021-36365

Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

9.8 2021-09-28 CVE-2021-36364

Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

9.8 2021-09-28 CVE-2021-36363

Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

5.4 2021-09-15 CVE-2021-38156

In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

6.1 2021-08-13 CVE-2021-37352

An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.

5.3 2021-08-13 CVE-2021-37351

Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.

9.8 2021-08-13 CVE-2021-37350

Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

7.8 2021-08-13 CVE-2021-37349

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.

7.5 2021-08-13 CVE-2021-37348

Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.

7.8 2021-08-13 CVE-2021-37347

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.

7.8 2021-08-13 CVE-2021-37345

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.

8.8 2021-08-13 CVE-2021-37343

A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.

7.2 2021-06-07 CVE-2021-3277

Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.

9.8 2021-05-24 CVE-2020-28910

Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.

8.8 2021-05-24 CVE-2020-28906

Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.

CWE : Common Weakness Enumeration

%idName
36% (16) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
13% (6) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...
9% (4) CWE-276 Incorrect Default Permissions
9% (4) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...
6% (3) CWE-732 Incorrect Permission Assignment for Critical Resource
4% (2) CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
4% (2) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...
2% (1) CWE-552 Files or Directories Accessible to External Parties
2% (1) CWE-434 Unrestricted Upload of File with Dangerous Type
2% (1) CWE-345 Insufficient Verification of Data Authenticity
2% (1) CWE-269 Improper Privilege Management
2% (1) CWE-94 Failure to Control Generation of Code ('Code Injection')
2% (1) CWE-74 Failure to Sanitize Data into a Different Plane ('Injection')
2% (1) CWE-20 Improper Input Validation

Snort® IPS/IDS

Date Description
2021-02-18 Nagios XI mibs.php remote command injection attempt
RuleID : 56880 - Type : SERVER-WEBAPP - Revision : 1
2021-02-18 Nagios XI mibs.php remote command injection attempt
RuleID : 56879 - Type : SERVER-WEBAPP - Revision : 1
2021-02-18 Nagios XI mibs.php remote command injection attempt
RuleID : 56878 - Type : SERVER-WEBAPP - Revision : 1
2021-02-18 Nagios XI mibs.php remote command injection attempt
RuleID : 56877 - Type : SERVER-WEBAPP - Revision : 1
2019-01-08 Nagios XI cmdsubsys.php command injection attempt
RuleID : 48484 - Type : SERVER-WEBAPP - Revision : 1
2018-12-28 Nagios XI magpie_debug.php command argument injection attempt
RuleID : 48443 - Type : SERVER-WEBAPP - Revision : 1
2017-01-18 Nagios Core Configuration Manager command injection attempt
RuleID : 41030 - Type : SERVER-WEBAPP - Revision : 2
2017-01-18 Nagios Core Configuration Manager SQL injection attempt
RuleID : 41029 - Type : SERVER-WEBAPP - Revision : 2
2014-01-11 Nagios core config manager tfpassword sql injection attempt
RuleID : 28908 - Type : SERVER-OTHER - Revision : 6

Nessus® Vulnerability Scanner

id Description
2013-12-26 Name: The remote host has a web application that is affected by a SQL injection vul...
File: nagiosxi_2012r2_4.nasl - Type: ACT_GATHER_INFO