CVE-2016-9565
28Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendepss 23%
de la publicación al arma0 días
Publicada en NVD15 dic
1ª PoC15 dic
probabilidad de explotación
23%top 3% de las CVE
explotación observada
noninguna fuente lo reporta
3 exploit(s) público(s)
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
Productos afectados
n/a · n/aPoCs públicas encontradas — 3
cve_referencepacketstormsecurity.com/files/140169/Nagios-Core-Curl-Command-Injection-Code-Execution.htmlno verificadocve_referencewww.exploit-db.com/exploits/40920/no verificadoexploitdbwww.exploit-db.com/exploits/40920no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/140169/Nagios-Core-Curl-Command-Injection-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0211.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0212.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0213.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0214.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0258.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0259.htmlhttp://seclists.org/fulldisclosure/2016/Dec/57https://legalhackers.com/advisories/Nagios-Exploit-Command-Injection-CVE-2016-9565-2008-4796.htmlhttps://security.gentoo.org/glsa/201702-26https://security.gentoo.org/glsa/201710-20https://www.exploit-db.com/exploits/40920/