nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-10736 CVE-2018-10736
HIGHNuclei
NagiosXI <= 5.4.12 - SQL injection
Record summary
CVE-2018-10736 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHNagiosXI <= 5.4.12 - SQL injectionCVSS 7.2
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
Impact
Authenticated administrators can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire Nagios XI instance.
Remediation
Upgrade to Nagios XI version 5.4.13 or later.
WeaknessesCWE-89
AuthorsDhiyaneshDK
Template tagscvecve2018nagiossqlivuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Shodan: http.title:"nagios xi"
FOFA: app="Nagios-XI"
FOFA: title="nagios xi"
FOFA: app="nagios-xi"
Google: intitle:"nagios xi"
https://github.com/0ps/pocassistdb https://github.com/jweny/pocassistdb https://vulners.com/seebug/SSV:97266
Source: ProjectDiscovery
References
2seebug.org
https://www.seebug.org/vuldb/ssvid-97266