LWN.net Logo

zabbix: multiple cross-site scripting vulnerabilities

Package(s):zabbix CVE #(s):CVE-2011-4615 CVE-2011-5027
Created:January 9, 2012 Updated:January 11, 2012
Description: From the CVE entries:

Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php. (CVE-2011-4615)

Cross-site scripting (XSS) vulnerability in ZABBIX before 1.8.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the profiler. (CVE-2011-5027)

Alerts:
Fedora FEDORA-2011-17560 2011-12-30
Fedora FEDORA-2011-17559 2011-12-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds