← Back

Pnp4nagios

pnp4nagios

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Pnp4nagios
pnp4nagios

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pnp4nagios
1Pnp4nagios
Nov 21, 2024
Jul 15, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.
1Pnp4nagios
1Pnp4nagios
Nov 21, 2024
Jul 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
1Pnp4nagios
1Pnp4nagios
May 13, 2026
Nov 16, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivile...Show more
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.Show less
1Pnp4nagios
1Pnp4nagios
May 6, 2026
Jul 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_pa...Show more
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element.Show less
2Op5
Pnp4nagios
2Monitor
Pnp4nagios
May 6, 2026
Jul 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properl...Show more
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.Show less
1Pnp4nagios
1Pnp4nagios
Apr 29, 2026
Aug 12, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain the Gearman shared secret by reading the file.