Nagios XI version xi-5.7.5는 OS 명령 삽입의 영향을 받습니다. 인증된 사용자가 제어하는 입력을 단일 HTTP 요청에서 부적절하게 정제하기 때문에 /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php 파일에 취약점이 존재하며, 이로 인해 Nagios XI 서버에서 OS 명령 삽입이 발생할 수 있습니다.
Nagios XI version xi-5.7.5는 OS 명령 삽입의 영향을 받습니다. 인증된 사용자가 제어하는 입력을 단일 HTTP 요청에서 부적절하게 정제하기 때문에 /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php 파일에 취약점이 존재하며, 이로 인해 Nagios XI 서버에서 OS 명령 삽입이 발생할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.