SQL-injection in Nagios - CVE-2018-8733
Published: May 31, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability exists due to authentication bypass vulnerability in the core config manager. A remote attacker can send a specially crafted HTTP request to vulnerable script, bypass authentication and execute arbitrary SQL commands in web application database.
Successful exploitation of the vulnerability may allow an attacker to gain administrative access to vulnerable web application.
Affected software
How to mitigate CVE-2018-8733
Links to Public Exploits and PoC-codes
- Exploit #6213 - Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root (June 17, 2021)
- Exploit #1938 - Nagios-XI-5.2.6-9-5.3-5.4-Chained-Remote-Root-Exploit-Fixed (Fixed exploit for Nagios CVE-2018-8733, CVE-2018-8734, CVE-2018-8735, CVE-2018-8736 https://www.exploit-db.com/exploits/44560/) (March 18, 2020)
- Exploit #1827 - Nagios XI Chained Remote Code Execution (March 18, 2020)