Exploitation Summary
EIP tracks 2 public exploits for CVE-2012-10029.
PoCs published by Metasploit, including Metasploit module exploits/unix/webapp/nagios_graph_explorer.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Nagios XI Network Monitor's Graph Explorer component. It authenticates as a user and injects a payload into the 'host' parameter of visApi.php, leading to remote code execution.
Description
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.
Exploits (2)
This Metasploit module exploits a command injection vulnerability in Nagios XI Network Monitor's Graph Explorer component. It authenticates as a user and injects a payload into the 'host' parameter of visApi.php, leading to remote code execution.
This Metasploit module exploits a command injection vulnerability in Nagios XI's Graph Explorer component (CVE-2012-10029). It authenticates as a user, then injects a payload via the 'host' parameter in visApi.php, leading to remote code execution.
References (5)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N