CVE-2013-6875
26.11.2013, 16:55
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.
Vendor | Product | Version |
---|---|---|
nagios | nagios_xi | 𝑥 ≤ 2012r2.3 |
nagios | nagios_xi | 2012r1.0:r1.0 |
nagios | nagios_xi | 2012r1.1:r1.1 |
nagios | nagios_xi | 2012r1.2:r1.2 |
nagios | nagios_xi | 2012r1.3:r1.3 |
nagios | nagios_xi | 2012r1.4:r1.4 |
nagios | nagios_xi | 2012r1.5:r1.5 |
nagios | nagios_xi | 2012r1.6:r1.6 |
nagios | nagios_xi | 2012r1.7:r1.7 |
nagios | nagios_xi | 2012r1.8:r1.8 |
nagios | nagios_xi | 2012r1.9:r1.9 |
nagios | nagios_xi | 2012r2.0:r2.0 |
nagios | nagios_xi | 2012r2.1:r2.1 |
nagios | nagios_xi | 2012r2.2:r2.2 |
𝑥
= Vulnerable software versions
References