Nagios XI 2011R1.9 Multiple SQL Injection Vulnerabilities

Medium Nessus Network Monitor Plugin ID 8364


A vulnerable version of Nagios XI has been detected.


Nagios XI 2011R1.9 is affected by multiple SQL injection vulnerabilities due to failure to sanitize user input. Scripts containing these vulnerabilities are the 'hostgroups.php', 'services.php', 'hosts.php', and 'servicegroups.php' scripts. Successful exploitation of these vulnerabilities would allow the attacker to access and modify data and compromise the application. Note that the attacker must be authenticated to exploit these vulnerabilities.


Upgrade to Nagios XI CCM 2012 Full Beta or higher.

See Also

Plugin Details

Severity: Medium

ID: 8364

Family: CGI

Published: 2014/08/25

Modified: 2016/02/05

Dependencies: 3558

Nessus ID: 64690

Risk Information

Risk Factor: Medium


Base Score: 6.5

Temporal Score: 5.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:ND


Base Score: 6.2

Temporal Score: 5.7


Temporal Vector: CVSS3#E:F/RL:O/RC:X

Vulnerability Information

CPE: cpe:/a:nagios:nagios_xi

Patch Publication Date: 2012/06/07

Vulnerability Publication Date: 2012/11/30

Reference Information

BID: 56761