CVE-2016-9565
CRITICALNagios < 4.2.1 - Arbitrary File Read and Write via Spoofed RSS Feed Response
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-9565. PoCs published by Dawid Golunski.
AI-analyzed exploit summary This exploit leverages a command injection vulnerability in Nagios Core < 4.2.0 via crafted User-Agent headers to inject curl commands, exfiltrate sensitive files, and deploy a PHP backdoor for reverse shell access.
Description
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
Exploits (1)
This exploit leverages a command injection vulnerability in Nagios Core < 4.2.0 via crafted User-Agent headers to inject curl commands, exfiltrate sensitive files, and deploy a PHP backdoor for reverse shell access.
References (16)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H