CVE-2018-8734: SQL Injection
Published Apr 18, 2018
·Updated
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.
Affected Software
1 affected component
Nagios Nagios XI>=5.2.0<5.4.13
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios XI core config managerto a version that resolves this vulnerability.Fixed in 5.4.13
Event History
Apr 18, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8734?
CVE-2018-8734 has a medium severity rating due to its potential to allow unauthorized SQL command execution.
2
How do I fix CVE-2018-8734?
To fix CVE-2018-8734, upgrade Nagios XI to version 5.4.13 or later.
3
What software is affected by CVE-2018-8734?
CVE-2018-8734 affects Nagios XI versions 5.2.x through 5.4.12.
4
Can CVE-2018-8734 be exploited remotely?
Yes, CVE-2018-8734 can be exploited remotely by attackers targeting the vulnerable parameter.
5
What type of vulnerability is CVE-2018-8734?
CVE-2018-8734 is an SQL injection vulnerability.