Description
|
|
Security Assessment has reported a vulnerability in Nagios XI, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed via the "tfPassword" POST parameter to /nagiosql/index.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerability is reported in versions prior to 2012R2.4.
|