LWN.net Logo

nagios: cross-site scripting

Package(s):nagios3 CVE #(s):CVE-2011-1523 CVE-2011-2179
Created:June 16, 2011 Updated:April 2, 2012
Description:

From the Ubuntu advisory:

Stefan Schurtz discovered than Nagios did not properly sanitize its input when processing certain requests, resulting in cross-site scripting (XSS) vulnerabilities. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain.

Alerts:
openSUSE openSUSE-SU-2011:0836-1 2011-07-25
openSUSE openSUSE-SU-2011:0833-1 2011-07-25
Ubuntu USN-1151-1 2011-06-15
Mandriva MDVSA-2012:049 2012-04-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds