nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-10735 CVE-2018-10735
HIGHNuclei
NagiosXI <= 5.4.12 `commandline.php` SQL injection
Record summary
CVE-2018-10735 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHNagiosXI <= 5.4.12 `commandline.php` SQL injectionCVSS 7.2
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
Impact
Authenticated administrators can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire Nagios XI instance.
Remediation
Upgrade to Nagios XI version 5.4.13 or later.
WeaknessesCWE-89
AuthorsDhiyaneshDk
Template tagscvecve2018nagiossqlivuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Shodan: http.title:"nagios xi"
FOFA: app="Nagios-XI"
FOFA: title="nagios xi"
FOFA: app="nagios-xi"
Google: intitle:"nagios xi"
https://vulners.com/seebug/SSV:97266 https://github.com/chaitin/xray/blob/master/pocs/nagio-cve-2018-10735.yml
Source: ProjectDiscovery
References
2seebug.org
https://www.seebug.org/vuldb/ssvid-97265