CVE-2012-10029: Nagios XI Network Monitor Graph Explorer Component < 1.3 Authenticated Command Injection
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in visApi.php. An authenticated user can inject system commands via unsanitized parameters such as host, resulting in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-10029?
CVE-2012-10029 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2012-10029?
To fix CVE-2012-10029, upgrade Nagios XI Network Monitor to version 1.3 or later.
Who is affected by CVE-2012-10029?
CVE-2012-10029 affects users of Nagios XI Network Monitor prior to version 1.3.
What component contains the vulnerability in CVE-2012-10029?
The vulnerability in CVE-2012-10029 is found in the Graph Explorer component, specifically in the visApi.php file.
What kind of attack can be executed via CVE-2012-10029?
CVE-2012-10029 allows authenticated users to perform command injection attacks, potentially leading to remote code execution.