CVE-2009-2288

statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
nagiosnagios
𝑥
≤ 3.1.0
nagiosnagios
1.0
nagiosnagios
1.0b1:b1
nagiosnagios
1.0b2:b2
nagiosnagios
1.0b4:b4
nagiosnagios
1.1
nagiosnagios
1.4.1
nagiosnagios
2.0
nagiosnagios
2.0b4:b4
nagiosnagios
2.7
nagiosnagios
2.10
nagiosnagios
3.0
nagiosnagios
3.0:alpha1
nagiosnagios
3.0:alpha2
nagiosnagios
3.0:alpha3
nagiosnagios
3.0:alpha4
nagiosnagios
3.0:beta1
nagiosnagios
3.0:beta2
nagiosnagios
3.0:beta3
nagiosnagios
3.0:beta4
nagiosnagios
3.0:beta5
nagiosnagios
3.0:beta6
nagiosnagios
3.0:beta7
nagiosnagios
3.0:rc1
nagiosnagios
3.0:rc2
nagiosnagios
3.0:rc3
nagiosnagios
3.0.1
nagiosnagios
3.0.2
nagiosnagios
3.0.3
nagiosnagios
3.0.4
nagiosnagios
3.0.5
nagiosnagios
3.0.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nagios
jaunty
dne
intrepid
dne
hardy
dne
dapper
not-affected
nagios2
jaunty
dne
intrepid
dne
hardy
Fixed 2.11-1ubuntu1.5
released
dapper
dne
nagios3
jaunty
Fixed 3.0.6-2ubuntu1.1
released
intrepid
Fixed 3.0.2-1ubuntu1.2
released
hardy
dne
dapper
dne