7.5
CVSSv2

CVE-2013-6875

Published: 26/11/2013 Updated: 27/11/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI prior to 2012R2.4 allows remote malicious users to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

nagios nagios xi 2012r2.1

nagios nagios xi 2012r1.9

nagios nagios xi 2012r1.2

nagios nagios xi 2012r1.0

nagios nagios xi

nagios nagios xi 2012r2.2

nagios nagios xi 2012

nagios nagios xi 2012r1.7

nagios nagios xi 2012r1.6

nagios nagios xi 2012r1.5

nagios nagios xi 2012r1.4

nagios nagios xi 2012r2.0

nagios nagios xi 2012r1.8

nagios nagios xi 2012r1.3

nagios nagios xi 2012r1.1

Exploits

source: wwwsecurityfocuscom/bid/63754/info Nagios XI is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlyi ...