Record summary

CVE-2013-1362 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.

Description

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBNagios Remote Plugin Executor - Arbitrary Command Execution (Metasploit)ExploitDB exploitby MetasploitNot analyzed1 file
ExploitDB

PoC details
MetasploitNagios Remote Plugin Executor Arbitrary Command ExecutionMetasploit exploitby Rudolph Pereir +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

7