[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-6875Date: (C)2013-11-28   (M)2023-12-22


SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-55695
http://assets.nagios.com/downloads/nagiosxi/CHANGES-2012.TXT
http://www.security-assessment.com/files/documents/advisory/NagiosQL%20Core%20Config%20Manager%20SQL%20Injection%20Vulnerability%20Advisory%20-%20DA.pdf

CPE    16
cpe:/a:nagios:nagios_xi:2012r1.9
cpe:/a:nagios:nagios_xi:2012r1.8
cpe:/a:nagios:nagios_xi:2012r1.7
cpe:/a:nagios:nagios_xi:2012r1.6
...
CWE    1
CWE-89

© SecPod Technologies