CVE-2008-5027
Last modified
CVE-2008-5027 is a vulnerability of currently unknown severity. The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization checks, and trigger execution of arbitrary programs by this process, via an (a) custom form or a (b) browser addon.. EPSS estimates a 6.74% chance of exploitation in the next 30 days.
Description
The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization checks, and trigger execution of arbitrary programs by this process, via an (a) custom form or a (b) browser addon.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nagios | Nagios | <= 3.0.4 |
| Nagios | Nagios | 1.0 |
| Nagios | Nagios | 1.0_b1 |
| Nagios | Nagios | 1.0_b2 |
| Nagios | Nagios | 1.0_b3 |
| Nagios | Nagios | 1.0b1 |
| Nagios | Nagios | 1.0b2 |
| Nagios | Nagios | 1.0b3 |
| Nagios | Nagios | 1.0b4 |
| Nagios | Nagios | 1.0b5 |
| Nagios | Nagios | 1.0b6 |
| Nagios | Nagios | 1.1 |
| Nagios | Nagios | 1.2 |
| Nagios | Nagios | 1.3 |
| Nagios | Nagios | 1.4 |
| Nagios | Nagios | 1.4.1 |
| Nagios | Nagios | 2.0 |
| Nagios | Nagios | 2.0b1 |
| Nagios | Nagios | 2.0b2 |
| Nagios | Nagios | 2.0b3 |
| Nagios | Nagios | 2.0b4 |
| Nagios | Nagios | 2.0b5 |
| Nagios | Nagios | 2.0b6 |
| Nagios | Nagios | 2.0rc1 |
| Nagios | Nagios | 2.0rc2 |
| Nagios | Nagios | 2.1 |
| Nagios | Nagios | 2.2 |
| Nagios | Nagios | 2.3 |
| Nagios | Nagios | 2.3.1 |
| Nagios | Nagios | 2.4 |
| Nagios | Nagios | 2.5 |
| Nagios | Nagios | 2.7 |
| Nagios | Nagios | 2.8 |
| Nagios | Nagios | 2.9 |
| Nagios | Nagios | 2.10 |
| Nagios | Nagios | 2.11 |
| Nagios | Nagios | 3.0 |
| Nagios | Nagios | 3.0.1 |
| Nagios | Nagios | 3.0.2 |
| Nagios | Nagios | 3.0.3 |
| Op5 | Monitor | <= 4.0.0 |
| Op5 | Monitor | 2.4 |
| Op5 | Monitor | 2.6 |
| Op5 | Monitor | 2.8 |
| Op5 | Monitor | 3.0 |
| Op5 | Monitor | 3.0.0 |
| Op5 | Monitor | 3.2 |
| Op5 | Monitor | 3.2.4 |
| Op5 | Monitor | 3.3.1 |
| Op5 | Monitor | 3.3.2 |
Showing 50 of 51 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5027?
How severe is CVE-2008-5027?
How do I fix CVE-2008-5027?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-5021nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x befo…
- CVE-2008-5022The nsXMLHttpRequest::NotifyEventListeners method in Firefox…
- CVE-2008-5023Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and S…
- CVE-2008-5024Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.1…
- CVE-2008-5025Stack-based buffer overflow in the hfs_cat_find_brec functio…
- CVE-2008-5026Microsoft SharePoint uses URLs with the same hostname and po…
- CVE-2008-5028Cross-site request forgery (CSRF) vulnerability in cmd.cgi i…
- CVE-2008-5029The __scm_destroy function in net/core/scm.c in the Linux ke…
- CVE-2008-5030Heap-based buffer overflow in the cddb_read_disc_data functi…
- CVE-2008-5031Multiple integer overflows in Python 2.2.3 through 2.5.1, an…
- CVE-2008-5032Stack-based buffer overflow in VideoLAN VLC media player 0.5…
- CVE-2008-5033The chip_command function in drivers/media/video/tvaudio.c i…
Are you affected by CVE-2008-5027?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
