A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
https://www.nagios.com/downloads/nagios-xi/change-log/
http://packetstormsecurity.com/files/165978/Nagios-XI-Autodiscovery-Shell-Upload.html