openSUSE-SU-2013:0621Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00005.html CVE-2013-1362
Nagios Remote Plugin Executor - Arbitrary Command Execution (Metasploit)
Record summary
CVE-2013-1362 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBNagios Remote Plugin Executor - Arbitrary Command Execution (Metasploit)ExploitDB exploitby MetasploitNot analyzed1 file
MetasploitNagios Remote Plugin Executor Arbitrary Command ExecutionMetasploit exploitby Rudolph Pereir +1 moreNot analyzed1 file
References
7openSUSE-SU-2013:0624Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00006.html 20130221 OSEC-2013-01: nagios metacharacter filtering omissionmailing list
http://seclists.org/bugtraq/2013/Feb/119 24955exploit
http://www.exploit-db.com/exploits/24955 occamsec.com
http://www.occamsec.com/vulnerabilities.html bugzilla.novell.comConfirmation
https://bugzilla.novell.com/show_bug.cgi?id=807241 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-1362