Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-analyzer/nagios-core. | Oct 30, 2017 | Nov 10, 2008 |
| Suse | — | Upgrade nagios-develUpgrade nagiosUpgrade nagios-www | Dec 12, 2013 | Nov 10, 2008 |
| Ubuntu | — | Upgrade nagios2Upgrade nagios3 | Nov 8, 2024 | Nov 10, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub