{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2008-5028", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "[nagios-devel] 20081107 Security fixes completed", "refsource" : "MLIST", "url" : "http://sourceforge.net/mailarchive/forum.php?thread_name=4914396D.5010009%40op5.se&forum_name=nagios-devel" }, { "name" : "[oss-security] 20081106 CVE request: Nagios (two issues)", "refsource" : "MLIST", "url" : "http://www.openwall.com/lists/oss-security/2008/11/06/2" }, { "name" : "http://git.op5.org/git/?p=nagios.git;a=commit;h=814d8d4d1a73f7151eeed187c0667585d79fea18", "refsource" : "CONFIRM", "url" : "http://git.op5.org/git/?p=nagios.git;a=commit;h=814d8d4d1a73f7151eeed187c0667585d79fea18" }, { "name" : "http://www.op5.com/support/news/389-important-security-fix-available-for-op5-monitor", "refsource" : "CONFIRM", "url" : "http://www.op5.com/support/news/389-important-security-fix-available-for-op5-monitor" }, { "name" : "GLSA-200907-15", "refsource" : "GENTOO", "url" : "http://security.gentoo.org/glsa/glsa-200907-15.xml" }, { "name" : "HPSBMA02419", "refsource" : "HP", "url" : "http://marc.info/?l=bugtraq&m=124156641928637&w=2" }, { "name" : "SSRT090060", "refsource" : "HP", "url" : "http://marc.info/?l=bugtraq&m=124156641928637&w=2" }, { "name" : "USN-698-3", "refsource" : "UBUNTU", "url" : "https://www.ubuntu.com/usn/USN-698-3/" }, { "name" : "49678", "refsource" : "OSVDB", "url" : "http://osvdb.org/49678" }, { "name" : "1022165", "refsource" : "SECTRACK", "url" : "http://www.securitytracker.com/id?1022165" }, { "name" : "32610", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/32610" }, { "name" : "33320", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/33320" }, { "name" : "35002", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/35002" }, { "name" : "32630", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/32630" }, { "name" : "ADV-2008-3029", "refsource" : "VUPEN", "url" : "http://www.vupen.com/english/advisories/2008/3029" }, { "name" : "ADV-2009-1256", "refsource" : "VUPEN", "url" : "http://www.vupen.com/english/advisories/2009/1256" }, { "name" : "nagios-cmd-csrf(46426)", "refsource" : "XF", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/46426" }, { "name" : "op5monitor-unspecified-csrf(46521)", "refsource" : "XF", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/46521" } ] } }