Short Name |
HTTP:NAGIOS-CONFMGR-SQLINJ |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Nagios Core Config Manager tfPassword Parameter SQL Injection |
Release Date |
2013/12/18 |
Update Number |
2328 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known issue against Nagios Core Config Manager. The issue is due to insufficient sanitization of user-supplied input received via the tfPassword parameter. A successful attack can lead to remote code execution.
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.