NagiosQL "SETS[path][physical]" and "SETS[path][IT]" PHP File Inclusion Vulnerability
Description
A vulnerability has been identified in NagiosQL, which could be exploited by remote attackers to compromise a vulnerable web server. This issue is caused by input validation errors in the "functions/prepend_adm.php" script when processing the "SETS[path][physical]" and "SETS[path][IT]" parameters, which could be exploited by remote attackers to include malicious PHP scripts and execute arbitrary commands with the privileges of the web server.
Vulnerable Products
Vulnerable Software: NagiosQL version 2.00-P00 and prior