First published: Tue Nov 26 2013(Updated: )
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios | <=2012r2.3 | |
Nagios | =2012-rc2 | |
Nagios | =2012-rc3 | |
Nagios | =2012-rc4 | |
Nagios | =2012r1.0 | |
Nagios | =2012r1.1 | |
Nagios | =2012r1.2 | |
Nagios | =2012r1.3 | |
Nagios | =2012r1.4 | |
Nagios | =2012r1.5 | |
Nagios | =2012r1.6 | |
Nagios | =2012r1.7 | |
Nagios | =2012r1.8 | |
Nagios | =2012r1.9 | |
Nagios | =2012r2.0 | |
Nagios | =2012r2.1 | |
Nagios | =2012r2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.