Main
Vulnerability Database
Exploits
ID:5299 - Exploit for OS Command Injection in Nagios XI - CVE-2020-35578
ID:5299 - Exploit for OS Command Injection in Nagios XI - CVE-2020-35578
Published: April 16, 2021
Vulnerability identifier: #VU49671
Vulnerability risk: Low
CVE-ID: CVE-2020-35578
CWE-ID: CWE-78
Exploitation vector: Remote access
Vulnerable software:
Nagios XI
Nagios XI
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the Manage Plugins page during a plugin upload. A remote privileged user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Remediation
Install updates from vendor's website.