CVE-2013-6875

SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
nagiosnagios_xi
𝑥
≤ 2012r2.3
nagiosnagios_xi
2012r1.0:r1.0
nagiosnagios_xi
2012r1.1:r1.1
nagiosnagios_xi
2012r1.2:r1.2
nagiosnagios_xi
2012r1.3:r1.3
nagiosnagios_xi
2012r1.4:r1.4
nagiosnagios_xi
2012r1.5:r1.5
nagiosnagios_xi
2012r1.6:r1.6
nagiosnagios_xi
2012r1.7:r1.7
nagiosnagios_xi
2012r1.8:r1.8
nagiosnagios_xi
2012r1.9:r1.9
nagiosnagios_xi
2012r2.0:r2.0
nagiosnagios_xi
2012r2.1:r2.1
nagiosnagios_xi
2012r2.2:r2.2
𝑥
= Vulnerable software versions