Nagios XI contains a flaw that is due to the includes/components/autodiscovery/index.php script failing to properly filter input passed via the 'address' parameter. With a specially crafted job, a remote attacker can inject arbitrary commands that will be run with the privileges of the running process. Note that any user can submit a new job, even user accounts with read-only access.
Disclosure Timeline:
Disclosure Date :2013-02-03
Exploit Publish Date :2013-02-03