Description
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version before 1.3
Credits
Daniel Compton
References
raw.githubusercontent.com/...webapp/nagios_graph_explorer.rb
www.exploit-db.com/exploits/23227
packetstorm.news/files/id/118705/
raw.githubusercontent.com/...webapp/nagios_graph_explorer.rb
www.exploit-db.com/exploits/23227
packetstorm.news/files/id/118705/
www.nagios.com/products/nagios-xi/
www.vulncheck.com/...plorer-component-auth-command-injection