Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-13723

Опубликовано: 04 фев. 2025
Источник: debian

Описание

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
check-mkremovedpackage
nagvisfixed1:1.9.42-1package
nagvisno-dsabookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2025/02/04/4

Связанные уязвимости

CVSS3: 7.2
ubuntu
около 1 года назад

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.

CVSS3: 7.2
nvd
около 1 года назад

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.

CVSS3: 7.2
github
около 1 года назад

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.