HTTP: Nagios XI Custom-includes Manage.php Rename_file Directory Traversal

This signature detects attempts to exploit a known vulnerability against Nagios XI. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.

Affected Products

Nagios nagios_xi

Short Name
HTTP:DIR:NAGIOS-XI-CIM-DIRTRV
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2021-3277 CVE-2023-48085 Custom-includes Directory Manage.php Nagios Rename_file Traversal XI
Release Date
06/22/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3692
False Positive
Unknown
Vendors

Nagios

CVSS Score

6.5

Found a potential security threat?