Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.nagios.com/products/security/ | vendor advisory |
https://www.nagios.com/downloads/nagios-xi/change-log/ | product vendor advisory release notes |
http://packetstormsecurity.com/files/152496/Nagios-XI-5.5.10-XSS-Remote-Code-Execution.html | third party advisory vdb entry |