
We found results for “”
CVE-2016-9565
Good to know:

Date: December 15, 2016
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.
Language: PHP
Severity Score
Related Resources (18)
Severity Score
Weakness Type (CWE)
Improper Access Control
CWE-284Top Fix

Upgrade Version
Upgrade to version travi/framework - 0.12.2;travi/framework - 0.12.0;travi/framework - 0.11.3;travi/framework - 0.12.3;travi/framework - v0.14.0;travi/framework - 0.11.1;travi/framework - 0.10.0;travi/framework - 0.12.1;travi/framework - 0.13.0;travi/framework - 0.11.2;travi/framework - 0.11.0;tdt/core - v4.0.0;kellan/magpierss - no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |