#VU13097 SQL-injection in Nagios - CVE-2018-8733
Published: May 31, 2018 / Updated: June 17, 2021
Nagios
nagios.org
Description
The vulnerability exists due to authentication bypass vulnerability in the core config manager. A remote attacker can send a specially crafted HTTP request to vulnerable script, bypass authentication and execute arbitrary SQL commands in web application database.
Successful exploitation of the vulnerability may allow an attacker to gain administrative access to vulnerable web application.