statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.
2009-07-01T13:00:01.827
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nagios | nagios | ≤ 3.1.0 | Yes |
Application | nagios | nagios | 1.0 | Yes |
Application | nagios | nagios | 1.0b1 | Yes |
Application | nagios | nagios | 1.0b2 | Yes |
Application | nagios | nagios | 1.0b4 | Yes |
Application | nagios | nagios | 1.1 | Yes |
Application | nagios | nagios | 1.4.1 | Yes |
Application | nagios | nagios | 2.0 | Yes |
Application | nagios | nagios | 2.0b4 | Yes |
Application | nagios | nagios | 2.7 | Yes |
Application | nagios | nagios | 2.10 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0 | Yes |
Application | nagios | nagios | 3.0.1 | Yes |
Application | nagios | nagios | 3.0.2 | Yes |
Application | nagios | nagios | 3.0.3 | Yes |
Application | nagios | nagios | 3.0.4 | Yes |
Application | nagios | nagios | 3.0.5 | Yes |
Application | nagios | nagios | 3.0.6 | Yes |