|
|
| |
|
| |
nagios: cross-site scripting
| Package(s): | nagios3 |
CVE #(s): | CVE-2011-1523
CVE-2011-2179
|
| Created: | June 16, 2011 |
Updated: | April 2, 2012 |
| Description: |
From the Ubuntu advisory:
Stefan Schurtz discovered than Nagios did not properly sanitize its input
when processing certain requests, resulting in cross-site scripting (XSS)
vulnerabilities. With cross-site scripting vulnerabilities, if a user were
tricked into viewing server output during a crafted server request, a
remote attacker could exploit this to modify the contents, or steal
confidential data, within the same domain.
|
| Alerts: |
|
( Log in to post comments)
|
|
|