Vulnerabilities > Pnp4Nagios > Pnp4Nagios > 0.6.20

DATE CVE VULNERABILITY TITLE RISK
2017-11-16 CVE-2017-16834 Incorrect Permission Assignment for Critical Resource vulnerability in Pnp4Nagios
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.
local
low complexity
pnp4nagios CWE-732
7.2
2014-07-11 CVE-2014-4908 Cross-Site Scripting vulnerability in Pnp4Nagios
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element.
network
pnp4nagios CWE-79
4.3
2014-07-11 CVE-2014-4907 Cross-Site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.
4.3