Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-6575 | Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution. |
Mon, 17 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios xi Graph Explorer
|
|
| CPEs | cpe:2.3:a:nagios:xi_graph_explorer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nagios xi Graph Explorer
|
Thu, 07 Aug 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios
Nagios nagios Nagios nagios Xi Nagios xi |
|
| Vendors & Products |
Nagios
Nagios nagios Nagios nagios Xi Nagios xi |
Wed, 06 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution. | |
| Title | Nagios XI Network Monitor Graph Explorer Component < 1.3 Authenticated Command Injection | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T11:13:56.158Z
Reserved: 2025-08-05T16:09:57.147Z
Link: CVE-2012-10029
Updated: 2025-08-06T15:13:08.263Z
Status : Deferred
Published: 2025-08-05T20:15:33.860
Modified: 2026-04-15T00:35:42.020
Link: CVE-2012-10029
No data.
OpenCVE Enrichment
Updated: 2025-08-06T15:12:49Z
EUVD