.. / CVE-2018-10735

Exploit for NagiosXI <= 5.4.12 `commandline.php` SQL injection (CVE-2018-10735)

Description:

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.

Nuclei Template

View the template here CVE-2018-10735.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-10735.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2018-10735
https://vulners.com/seebug/SSV:97266
https://github.com/chaitin/xray/blob/master/pocs/nagio-cve-2018-10735.yml