Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-48084 — Python program to dump all the databases, exploiting NagiosXI sqli vulnerability | Kitploit
Tools/GitHubGitHub/hamibubu/cve-2023-48084
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingDatabase Security
GitHubhamibubu/cve-2023-48084

CVE-2023-48084

Python program to dump all the databases, exploiting NagiosXI sqli vulnerability

View Repository
1102 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-48084

Python exploit for the CVE-2023-48084 -> Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

The exploit uses /admin/banner_message-ajaxhelper.php?action=acknowledge_banner_message&id=(<SQL COMMAND TO EXECUTE>) to execute SQL queries, and exploits a blind SQL injection...

Usage

Clone the repo and install the requirements.txt

git clone https://github.com/Hamibubu/CVE-2023-48084.git
cd CVE-2023-48084
pip install -r requirements.txt

Now execute the program, you need a non-admin session cookie, or an API token, example

python3 CVE-2023-48084.py --url https://monitored.htb/nagiosxi -a <token>
python3 CVE-2023-48084.py --url https://monitored.htb/nagiosxi -c <cookie>

NOTE

For default it will try to dump all the database starting from schemas, if you want it more fast, just look at the code and take the part that you need

Download Tool