Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4ccv-pj8j-48ph

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.

In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.

EPSS

Процентиль: 98%
0.22404
Средний

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.

EPSS

Процентиль: 98%
0.22404
Средний