CVE-2018-8734 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 52.6% (pctl 99)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 52.56% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-04-18 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| nagios | nagios xi |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit) | 2018-07-02 |
| exploit-db | Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root | 2018-04-30 |
References
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT
- https://blog.redactedsec.net/exploits/2018/04/26/nagios.html
- https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f
- https://www.exploit-db.com/exploits/44560/
- https://www.exploit-db.com/exploits/44969/
- https://www.nagios.com/downloads/nagios-xi/change-log/
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT
- https://blog.redactedsec.net/exploits/2018/04/26/nagios.html
- https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f
- https://www.exploit-db.com/exploits/44560/
- https://www.exploit-db.com/exploits/44969/
- https://www.nagios.com/downloads/nagios-xi/change-log/
→ the Explorer · watch your stack · NVD