vendor:
Nagios Core
by:
Dawid Golunski
9,8
CVSS
CRITICAL
Command Injection
78
CWE
Product Name: Nagios Core
Affected Version From: Nagios Core < 4.2.0
Affected Version To: Nagios Core < 4.2.0
Patch Exists: YES
Related CWE: CVE-2016-9565
CPE: a:nagios:nagios_core
Metasploit:
https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2016-9565/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-9566/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-9565/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2016
Nagios Core < 4.2.0 Curl Command Injection / Code Execution PoC Exploit
This PoC exploit can allow well-positioned attackers to extract and write arbitrary files on the Nagios server which can lead to arbitrary code execution on Nagios deployments that follow the official Nagios installation guidelines.
Mitigation:
Upgrade to Nagios Core 4.2.0 or later.