module
Nagios XI Chained Remote Code Execution
| Disclosed |
|---|
| Apr 17, 2018 |
Disclosed
Apr 17, 2018
Description
This module exploits a few different vulnerabilities in Nagios XI 5.2.6-5.4.12 to gain remote root access.
The steps are:
1. Issue a POST request to /nagiosql/admin/settings.php which sets the database user to root.
2. SQLi on /nagiosql/admin/helpedit.php allows us to enumerate API keys.
3. The API keys are then used to add an administrative user.
4. An authenticated session is established with the newly added user
5. Command Injection on /nagiosxi/backend/index.php allows us to execute the payload with nopasswd sudo,
giving us a root shell.
6. Remove the added admin user and reset the database user.
The steps are:
1. Issue a POST request to /nagiosql/admin/settings.php which sets the database user to root.
2. SQLi on /nagiosql/admin/helpedit.php allows us to enumerate API keys.
3. The API keys are then used to add an administrative user.
4. An authenticated session is established with the newly added user
5. Command Injection on /nagiosxi/backend/index.php allows us to execute the payload with nopasswd sudo,
giving us a root shell.
6. Remove the added admin user and reset the database user.
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.