CVE-2018-15708
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 89%
from disclosure to weapon70 days
Published on NVDNov 14
1st PoC+70d
metasploitNov 14
exploitation probability
89%top 1% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
Affected products
Nagios · Nagios XIpublic PoCs found — 5✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47039exploitdbwww.exploit-db.com/exploits/46221unverifiedgithubgithub.com/lkduy2602/Detecting-CVE-2018-15708-Vulnerabilities★ 0cve_referencepacketstormsecurity.com/files/153433/Nagios-XI-Magpie_debug.php-Root-Remote-Code-Execution.htmlunverifiedcve_referencewww.exploit-db.com/exploits/46221/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.