← All CVEs

CVE-2018-8734

critical · 9.8

SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.

9.8
CVSS
52.6%
EPSS (exploit prob.)
99th
EPSS percentile
2018-04-18
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
nagiosnagios_xi>= 5.2.0, < 5.4.13

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-8734