Nagios?XIÔ¶³ÌºÅÁîÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-03

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-20197£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Nagios XI 5.6.9 °æ±¾


·ì϶¸ÅÊö


Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¹æ»®¡£¸Ã¹æ»®Ö§³Ö¶ÔÀûÓᢷþÎñ¡¢²Ù×÷ϵͳµÈ½øÐÐ¼à¿ØºÍÔ¤¾¯¡£

Nagios XI 5.6.9°æ±¾ÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿Éͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâµÄ²Ù×÷ϵͳºÅÁî¡£


·ì϶ÑéÖ¤


POC: https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌ⣬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://www.nagios.org/¡£


²Î¿¼Á´½Ó


http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534