← Back

CVE-2013-6875

nvd nist
Published: Nov 26, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.

Affected (17)

Products: Nagios: Nagios Xi
1 product
Nagios Xi
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Nagios
Up to 2012r2.3
Version 2012 rc2
Version 2012 rc3
Version 2012 rc4
Version 2012r1.0
Version 2012r1.1
Version 2012r1.2
Version 2012r1.3
Version 2012r1.4
Version 2012r1.5
Version 2012r1.6
Version 2012r1.7
Version 2012r1.8
Version 2012r1.9
Version 2012r2.0
Version 2012r2.1
Version 2012r2.2

Timeline

No history available yet.