Sebastian Wolf

2 exploits Active since Aug 2017
CVE-2017-12847 WRITEUP MEDIUM WRITEUP
Nagios Core <4.3.3 - Privilege Escalation
Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a root script executes a "kill `cat /pathname/nagios.lock`" command.
CVSS 6.3
CVE-2023-37154 WRITEUP HIGH WRITEUP
Nagios nagios-plugins <2.4.5 - Command Injection
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.
CVSS 8.4