CVE-2009-2288

EUVD-2009-2284
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
nagiosnagios
𝑥
≤ 3.1.0
nagiosnagios
1.0
nagiosnagios
1.0b1:b1
nagiosnagios
1.0b2:b2
nagiosnagios
1.0b4:b4
nagiosnagios
1.1
nagiosnagios
1.4.1
nagiosnagios
2.0
nagiosnagios
2.0b4:b4
nagiosnagios
2.7
nagiosnagios
2.10
nagiosnagios
3.0
nagiosnagios
3.0:alpha1
nagiosnagios
3.0:alpha2
nagiosnagios
3.0:alpha3
nagiosnagios
3.0:alpha4
nagiosnagios
3.0:beta1
nagiosnagios
3.0:beta2
nagiosnagios
3.0:beta3
nagiosnagios
3.0:beta4
nagiosnagios
3.0:beta5
nagiosnagios
3.0:beta6
nagiosnagios
3.0:beta7
nagiosnagios
3.0:rc1
nagiosnagios
3.0:rc2
nagiosnagios
3.0:rc3
nagiosnagios
3.0.1
nagiosnagios
3.0.2
nagiosnagios
3.0.3
nagiosnagios
3.0.4
nagiosnagios
3.0.5
nagiosnagios
3.0.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nagios
dapper
not-affected
hardy
dne
intrepid
dne
jaunty
dne
nagios2
dapper
dne
hardy
Fixed 2.11-1ubuntu1.5
released
intrepid
dne
jaunty
dne
nagios3
dapper
dne
hardy
dne
intrepid
Fixed 3.0.2-1ubuntu1.2
released
jaunty
Fixed 3.0.6-2ubuntu1.1
released