The remote host is missing an update to nagios announced via advisory USN-698-1.
Details follow:
It was discovered that Nagios did not properly parse commands submitted using the web interface. An authenticated user could use a custom form or a browser addon to bypass security restrictions and submit unauthorized commands.
Solution: The problem can be corrected by upgrading your system to the following package versions: