Nagios?XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-01-03Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-20197£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Nagios XI 5.6.9 °æ±¾
Îó²î¸ÅÊö
Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¼Æ»®¡£¸Ã¼Æ»®Ö§³Ö¶ÔÓ¦ÓᢷþÎñ¡¢²Ù×÷ϵͳµÈ¾ÙÐÐ¼à¿ØºÍÔ¤¾¯¡£
Nagios XI 5.6.9°æ±¾Öб£´æÇå¾²Îó²î¡£¹¥»÷Õß¿Éͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâµÄ²Ù×÷ϵͳÏÂÁî¡£
Îó²îÑéÖ¤
POC: https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö²½·¥£ºhttps://www.nagios.org/¡£
²Î¿¼Á´½Ó
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534


¾©¹«Íø°²±¸11010802024551ºÅ