CVE-2013-7107

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
icingaicinga
𝑥
≤ 1.10.2
icingaicinga
0.8.0
icingaicinga
0.8.1
icingaicinga
0.8.2
icingaicinga
0.8.3
icingaicinga
0.8.4
icingaicinga
1.0
icingaicinga
1.0:rc1
icingaicinga
1.0.1
icingaicinga
1.0.2
icingaicinga
1.0.3
icingaicinga
1.2.0
icingaicinga
1.2.1
icingaicinga
1.3.0
icingaicinga
1.3.1
icingaicinga
1.4.0
icingaicinga
1.4.1
icingaicinga
1.6.0
icingaicinga
1.6.1
icingaicinga
1.6.2
icingaicinga
1.7.0
icingaicinga
1.7.1
icingaicinga
1.7.2
icingaicinga
1.7.3
icingaicinga
1.7.4
icingaicinga
1.8.0
icingaicinga
1.8.1
icingaicinga
1.8.2
icingaicinga
1.8.3
icingaicinga
1.8.4
icingaicinga
1.8.5
icingaicinga
1.9.0
icingaicinga
1.9.1
icingaicinga
1.9.2
icingaicinga
1.9.3
icingaicinga
1.9.4
icingaicinga
1.10.0
icingaicinga
1.10.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icinga
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
lucid
dne
nagios3
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
lucid
ignored