CVE-2020-35578
CVE-2020-35578
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/160948/Nagios-XI-5.7.x-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/162207/Nagios-XI-Remote-Code-Execution.htmlunverifiedexploitdbwww.exploit-db.com/exploits/49422unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →