Nagios XI '/nagiosxi/login.php' SQL Injection Vulnerability
BID:108446
CVE-2019-12279 |Info
Nagios XI '/nagiosxi/login.php' SQL Injection Vulnerability
| Bugtraq ID: | 108446 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-12279 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2019 12:00AM |
| Updated: | May 22 2019 12:00AM |
| Credit: | Jameel Nabbo |
| Vulnerable: |
Nagios Nagios XI 5.6.1 |
| Not Vulnerable: | |
Discussion
Nagios XI '/nagiosxi/login.php' SQL Injection Vulnerability
Nagios XI is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Nagios XI 5.6.1 is vulnerable; other versions may also be vulnerable.
Nagios XI is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Nagios XI 5.6.1 is vulnerable; other versions may also be vulnerable.
Exploit / POC
Nagios XI '/nagiosxi/login.php' SQL Injection Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
References
Nagios XI '/nagiosxi/login.php' SQL Injection Vulnerability
References:
References:
- Nagios XI Homepage (Nagios)
- Nagiosxi username sql injection (GitHub)