CVE-2009-2288
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 83%
from disclosure to weapon0 days
Published on NVDJul 1
1st PoCMay 22
metasploitJun 22
VulnCheck+4171d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/33051unverifiedexploitdbwww.exploit-db.com/exploits/16908unverifiedexploitdbwww.exploit-db.com/exploits/9861unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=126996888626964&w=2http://secunia.com/advisories/35543http://secunia.com/advisories/35688http://secunia.com/advisories/35692http://secunia.com/advisories/39227http://security.gentoo.org/glsa/glsa-200907-15.xmlhttp://tracker.nagios.org/view.php?id=15http://www.debian.org/security/2009/dsa-1825http://www.nagios.org/development/history/core-3x/http://www.securitytracker.com/id?1022503http://www.ubuntu.com/usn/USN-795-1http://www.vupen.com/english/advisories/2010/0750