CVE Vulnerabilities

CVE-2008-5027

Published: Nov 10, 2008 | Modified: Dec 08, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization checks, and trigger execution of arbitrary programs by this process, via an (a) custom form or a (b) browser addon.

Affected Software

Name Vendor Start Version End Version
Nagios Nagios * 3.0.4 (including)
Nagios Nagios 1.0 (including) 1.0 (including)
Nagios Nagios 1.0_b1 (including) 1.0_b1 (including)
Nagios Nagios 1.0_b2 (including) 1.0_b2 (including)
Nagios Nagios 1.0_b3 (including) 1.0_b3 (including)
Nagios Nagios 1.0b1 (including) 1.0b1 (including)
Nagios Nagios 1.0b2 (including) 1.0b2 (including)
Nagios Nagios 1.0b3 (including) 1.0b3 (including)
Nagios Nagios 1.0b4 (including) 1.0b4 (including)
Nagios Nagios 1.0b5 (including) 1.0b5 (including)
Nagios Nagios 1.0b6 (including) 1.0b6 (including)
Nagios Nagios 1.1 (including) 1.1 (including)
Nagios Nagios 1.2 (including) 1.2 (including)
Nagios Nagios 1.3 (including) 1.3 (including)
Nagios Nagios 1.4 (including) 1.4 (including)
Nagios Nagios 1.4.1 (including) 1.4.1 (including)
Nagios Nagios 2.0 (including) 2.0 (including)
Nagios Nagios 2.0b1 (including) 2.0b1 (including)
Nagios Nagios 2.0b2 (including) 2.0b2 (including)
Nagios Nagios 2.0b3 (including) 2.0b3 (including)
Nagios Nagios 2.0b4 (including) 2.0b4 (including)
Nagios Nagios 2.0b5 (including) 2.0b5 (including)
Nagios Nagios 2.0b6 (including) 2.0b6 (including)
Nagios Nagios 2.0rc1 (including) 2.0rc1 (including)
Nagios Nagios 2.0rc2 (including) 2.0rc2 (including)
Nagios Nagios 2.1 (including) 2.1 (including)
Nagios Nagios 2.2 (including) 2.2 (including)
Nagios Nagios 2.3 (including) 2.3 (including)
Nagios Nagios 2.3.1 (including) 2.3.1 (including)
Nagios Nagios 2.4 (including) 2.4 (including)
Nagios Nagios 2.5 (including) 2.5 (including)
Nagios Nagios 2.7 (including) 2.7 (including)
Nagios Nagios 2.8 (including) 2.8 (including)
Nagios Nagios 2.9 (including) 2.9 (including)
Nagios Nagios 2.10 (including) 2.10 (including)
Nagios Nagios 2.11 (including) 2.11 (including)
Nagios Nagios 3.0 (including) 3.0 (including)
Nagios Nagios 3.0-alpha1 (including) 3.0-alpha1 (including)
Nagios Nagios 3.0-alpha2 (including) 3.0-alpha2 (including)
Nagios Nagios 3.0-alpha3 (including) 3.0-alpha3 (including)
Nagios Nagios 3.0-alpha4 (including) 3.0-alpha4 (including)
Nagios Nagios 3.0-beta1 (including) 3.0-beta1 (including)
Nagios Nagios 3.0-beta2 (including) 3.0-beta2 (including)
Nagios Nagios 3.0-beta3 (including) 3.0-beta3 (including)
Nagios Nagios 3.0-beta4 (including) 3.0-beta4 (including)
Nagios Nagios 3.0-beta5 (including) 3.0-beta5 (including)
Nagios Nagios 3.0-beta6 (including) 3.0-beta6 (including)
Nagios Nagios 3.0-beta7 (including) 3.0-beta7 (including)
Nagios Nagios 3.0-rc1 (including) 3.0-rc1 (including)
Nagios Nagios 3.0-rc2 (including) 3.0-rc2 (including)
Nagios Nagios 3.0-rc3 (including) 3.0-rc3 (including)
Nagios Nagios 3.0.1 (including) 3.0.1 (including)
Nagios Nagios 3.0.2 (including) 3.0.2 (including)
Nagios Nagios 3.0.3 (including) 3.0.3 (including)
Monitor Op5 * 4.0.0 (including)
Monitor Op5 2.4 (including) 2.4 (including)
Monitor Op5 2.6 (including) 2.6 (including)
Monitor Op5 2.8 (including) 2.8 (including)
Monitor Op5 3.0 (including) 3.0 (including)
Monitor Op5 3.0.0 (including) 3.0.0 (including)
Monitor Op5 3.2 (including) 3.2 (including)
Monitor Op5 3.2.4 (including) 3.2.4 (including)
Monitor Op5 3.3.1 (including) 3.3.1 (including)
Monitor Op5 3.3.2 (including) 3.3.2 (including)
Monitor Op5 3.3.3 (including) 3.3.3 (including)
Nagios Ubuntu dapper *
Nagios Ubuntu gutsy *
Nagios2 Ubuntu gutsy *
Nagios2 Ubuntu hardy *
Nagios3 Ubuntu intrepid *
Nagios3 Ubuntu upstream *

References