NA

CVE-2023-48084

Published: 14/12/2023 Updated: 19/12/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Nagios XI before version 5.11.3 exists to contain a SQL injection vulnerability via the bulk modification tool.

Vulnerable Product Search on Vulmon Subscribe to Product

nagios nagios xi

Github Repositories

Python program to dump all the databases, exploiting NagiosXI sqli vulnerability

CVE-2023-48084 Python exploit for the CVE-2023-48084 -> Nagios XI before version 5113 was discovered to contain a SQL injection vulnerability via the bulk modification tool The exploit uses /admin/banner_message-ajaxhelperphp?action=acknowledge_banner_message&id=(<SQL COMMAND TO EXECUTE>) to execute SQL queries, and exploits a blind SQL injectio

Fixes broken syntax in the POC, automates the API_Token retrieval, stores the token as a variable and pipes into the fixed POC.

CVE-2023-48084- Fixes broken syntax in the POC, automates the API_Token retrieval, stores the token as a variable and pipes into the fixed POC