PoC Index

CVE-2018-8734

CRITICAL 9.8EPSS 52.6%

SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
52.56% chance of exploitation in the next 30 days, 99th percentile
Published
2018-04-18
Updated
2024-08-05

Metasploit modules (1)

ExploitDB entries (2)

References

Related