SQL-injection in Nagios - CVE-2018-8734
Published: May 31, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability exists due to insufficient validation of user-supplied input passed via the selInfoKey1 parameter. A remote attacker can send a specially crafted HTTP request to vulnerable script and execute arbitrary SQL commands in web application database.
Successful exploitation of the vulnerability may allow an attacker to gain administrative access to vulnerable web application.
Affected software
How to mitigate CVE-2018-8734
Links to Public Exploits and PoC-codes
- Exploit #6212 - Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root (June 17, 2021)
- Exploit #1937 - Nagios-XI-5.2.6-9-5.3-5.4-Chained-Remote-Root-Exploit-Fixed (Fixed exploit for Nagios CVE-2018-8733, CVE-2018-8734, CVE-2018-8735, CVE-2018-8736 https://www.exploit-db.com/exploits/44560/) (March 18, 2020)
- Exploit #1826 - Nagios XI Chained Remote Code Execution (March 18, 2020)