CVE-2020-28902: Command Injection
Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmdsubsys.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28902?
CVE-2020-28902 is a command injection vulnerability in Nagios Fusion 4.1.8 and earlier that allows privilege escalation from Apache to root.
How severe is CVE-2020-28902?
CVE-2020-28902 has a severity rating of 9.8 (critical).
What software is affected by CVE-2020-28902?
Nagios Fusion version 4.1.8 and earlier is affected by CVE-2020-28902.
How can I fix CVE-2020-28902?
To fix CVE-2020-28902, it is recommended to update Nagios Fusion to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2020-28902?
More information about CVE-2020-28902 can be found in the following references: [Link 1](http://packetstormsecurity.com/files/162783/Nagios-XI-Fusion-Privilege-Escalation-Cross-Site-Scripting-Code-Execution.html), [Link 2](https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/), [Link 3](https://www.nagios.com/downloads/nagios-xi/change-log/)