Nagios Expoit Video PoC

Nagios Core < 4.2.2 Curl Cmd Injection / Remote Code Execution (CVE-2016-9565)

Nagios Core < 4.2.4 Root Privilege Escalation (CVE-2016-9566)

Discovered by Dawid Golunski


The video below demonstrates how an attacker using the CVE-2016-9565 vulnerability in Nagios, could gain access to the Nagios server in the context of www-data/nagios user and escalate their privileges to root by exploiting the Root Privilege Escalation vulnerability CVE-2016-9566.

To receive updates on this as well as new vulnerabilities:

~~~~~~~~~~~ ~~~~~~~~~~~~~~~~
Interested in security / vulns / exploits ?
Check out the new project of the author of this advisory:
A Playground & Labs for security folks into HACKING &AMp;
the art of exploitation