Record summary

CVE-2018-10736 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHNagiosXI <= 5.4.12 - SQL injectionCVSS 7.2

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.

Impact

Authenticated administrators can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire Nagios XI instance.

Remediation

Upgrade to Nagios XI version 5.4.13 or later.

WeaknessesCWE-89
AuthorsDhiyaneshDK
Template tagscvecve2018nagiossqlivuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Shodan: http.title:"nagios xi"
FOFA: app="Nagios-XI"
FOFA: title="nagios xi"
FOFA: app="nagios-xi"
Google: intitle:"nagios xi"

Source: ProjectDiscovery

References

2