Nagios XI Snoopy magpie Remote Code Execution

Strike ID:
E18-5lzw1
CVSS:
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
t
Variants:
1
Year:
2018

Description

This strike exploits a remote code execution vulnerability in Nagios XI Snoopy component. The vulnerability resides in the lack of request sanitization when parsing the 'url' parameter within 'magpie_debug.php' file. By providing the '-o' flag within the parameter's value, an attacker is able to download a Php script from an arbitrary url and dump it to a publicly accessible path in order to execute commands on the target system.

CVE

References