← Vulnerability feed

Vulnerability record · CVE-2008-5028 · published 10 November 2008

CVE-2008-5028: Nagios cross-site request forgery vulnerability

Nagios · Nagios

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests.

6.8 CVSS 2.0 Medium EPSS 1.7% · top 24.0% CWE-352 · Cross-site request forgery
6.8CVSS 2.0 base score
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://git.op5.org/git/?p=nagios.git%3Ba=commit%3Bh=814d8d4d1a73f7151eeed187c0667585d79fea18
http://marc.info/?l=bugtraq&m=124156641928637&w=2
http://osvdb.org/49678
http://secunia.com/advisories/32610 Vendor Advisory
http://secunia.com/advisories/32630
http://secunia.com/advisories/33320
http://secunia.com/advisories/35002
http://security.gentoo.org/glsa/glsa-200907-15.xml
http://sourceforge.net/mailarchive/forum.php?thread_name=4914396D.5010009%40op5.se&forum_name=nagios-devel Patch
http://www.op5.com/support/news/389-important-security-fix-available-for-op5-monitor PatchVendor Advisory
http://www.openwall.com/lists/oss-security/2008/11/06/2
http://www.securitytracker.com/id?1022165
http://www.vupen.com/english/advisories/2008/3029
http://www.vupen.com/english/advisories/2009/1256
https://exchange.xforce.ibmcloud.com/vulnerabilities/46426
https://exchange.xforce.ibmcloud.com/vulnerabilities/46521
https://www.ubuntu.com/usn/USN-698-3/
http://git.op5.org/git/?p=nagios.git%3Ba=commit%3Bh=814d8d4d1a73f7151eeed187c0667585d79fea18
http://marc.info/?l=bugtraq&m=124156641928637&w=2
http://osvdb.org/49678
http://secunia.com/advisories/32610 Vendor Advisory
http://secunia.com/advisories/32630
http://secunia.com/advisories/33320
http://secunia.com/advisories/35002
http://security.gentoo.org/glsa/glsa-200907-15.xml
http://sourceforge.net/mailarchive/forum.php?thread_name=4914396D.5010009%40op5.se&forum_name=nagios-devel Patch
http://www.op5.com/support/news/389-important-security-fix-available-for-op5-monitor PatchVendor Advisory
http://www.openwall.com/lists/oss-security/2008/11/06/2
http://www.securitytracker.com/id?1022165
http://www.vupen.com/english/advisories/2008/3029
http://www.vupen.com/english/advisories/2009/1256
https://exchange.xforce.ibmcloud.com/vulnerabilities/46426
https://exchange.xforce.ibmcloud.com/vulnerabilities/46521
https://www.ubuntu.com/usn/USN-698-3/

Track CVE-2008-5028 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-0262op5 Monitor op5config command injection via password parameterThe op5config/welcome component in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 passes the password parameter to a she…EPSS 73%analysed10.0CVE-2012-0264Op5 monitor permissions and access controls vulnerabilityop5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impact via un…EPSS 4.4%10.0CVE-2012-0261op5 Monitor system-portal license.php command injectionThe license.php script in op5 Monitor's system-portal (before 1.6.2) and op5 Appliance (before 5.5.3) passes the timestamp parameter of an install ac…EPSS 74%analysed10.0CVE-2008-4796Snoopy project snoopy os command injection vulnerabilityThe _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamat…EPSS 9.0%10.0CVE-2002-1959Nagios vulnerabilityNagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.EPSS 3.9%9.8CVE-2016-0726Nagios hard-coded credentials vulnerabilityThe Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote at…EPSS 2.3%9.8CVE-2008-7313Snoopy command injection vulnerabilityThe _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE…EPSS 4.5%9.8CVE-2014-5009Snoopy command injection vulnerabilitySnoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.EPSS 4.7%

Source: NIST National Vulnerability Database (record CVE-2008-5028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.