Nagios?XIÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-01-03Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-20197£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Nagios XI 5.6.9 °æ±¾
Îó²î¸ÅÊö
Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¼Æ»®¡£¡£¡£¡£¸Ã¼Æ»®Ö§³Ö¶ÔÓ¦Óá¢Ð§ÀÍ¡¢²Ù×÷ϵͳµÈ¾ÙÐÐ¼à¿ØºÍÔ¤¾¯¡£¡£¡£¡£
Nagios XI 5.6.9°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâµÄ²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£
Îó²îÑéÖ¤
POC: https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÔÝδÐû²¼ÐÞ¸´²½·¥½â¾ö´ËÇå¾²ÎÊÌ⣬£¬£¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö²½·¥£ºhttps://www.nagios.org/¡£¡£¡£¡£
²Î¿¼Á´½Ó
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534