CVE-2008-5028
Publication date 10 November 2008
Last updated 24 July 2024
Ubuntu priority
Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests.
Status
Package | Ubuntu Release | Status |
---|---|---|
nagios | ||
nagios2 | ||
nagios3 | ||
Notes
mdeslaur
Nagios 1.x doesn't have the CMD_CHANGE commands, so remote attackers wouldn't be able to trigger arbitrary programs.
Patch details
Package | Patch details |
---|---|
nagios3 |