vendor:
Nagios3
by:
hdm
7.5
CVSS
HIGH
Metacharacter Injection
78
CWE
Product Name: Nagios3
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2009-2288, OSVDB-55281
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1141/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-2288/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-2288/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-3ebd4cb5-657f-11de-883a-00e0815b8da8/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2009
Nagios3 statuswml.cgi Ping Command Execution
This module abuses a metacharacter injection vulnerability in the Nagios3 statuswml.cgi script. This flaw is triggered when shell metacharacters are present in the parameters to the ping and traceroute commands.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in system commands.