Логотип exploitDog
bind:CVE-2020-36867
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-36867

Количество 3

Количество 3

nvd логотип

CVE-2020-36867

3 месяца назад

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or improperly escaped, allowing an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3qxh-pr59-jwh7

3 месяца назад

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or improperly escaped, allowing an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2025-14422

3 месяца назад

Уязвимость функции download() и export() инструмента для мониторинга Nagios XI, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-36867

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or improperly escaped, allowing an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.

CVSS3: 8.8
2%
Низкий
3 месяца назад
github логотип
GHSA-3qxh-pr59-jwh7

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or improperly escaped, allowing an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.

CVSS3: 8.8
2%
Низкий
3 месяца назад
fstec логотип
BDU:2025-14422

Уязвимость функции download() и export() инструмента для мониторинга Nagios XI, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

CVSS3: 8.8
2%
Низкий
3 месяца назад

Уязвимостей на страницу