4.3
CVSSv2

CVE-2011-1523

Published: 03/05/2011 Updated: 22/09/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the layer parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

nagios nagios 2.0b1

nagios nagios 2.0

nagios nagios 1.0b3

nagios nagios 1.0b2

nagios nagios 3.0

nagios nagios 2.0b5

nagios nagios 2.0b4

nagios nagios 1.2

nagios nagios 1.1

nagios nagios 1.0_b1

nagios nagios 1.0_b2

nagios nagios 3.0.3

nagios nagios 3.0.2

nagios nagios 2.1

nagios nagios 2.4

nagios nagios 3.0.1

nagios nagios 1.4.1

nagios nagios 2.5

nagios nagios 2.7

nagios nagios 2.10

nagios nagios 2.0b3

nagios nagios 2.0b2

nagios nagios 1.0b6

nagios nagios 1.0b5

nagios nagios 1.0b4

nagios nagios 1.0

nagios nagios 3.0.4

nagios nagios 3.0.5

nagios nagios 2.0rc2

nagios nagios 2.0rc1

nagios nagios 2.3.1

nagios nagios 2.8

nagios nagios 3.1.2

nagios nagios 2.0b6

nagios nagios 1.4

nagios nagios 1.3

nagios nagios 1.0_b3

nagios nagios 1.0b1

nagios nagios 2.9

nagios nagios 2.2

nagios nagios 2.3

nagios nagios 3.1.0

nagios nagios 2.11

nagios nagios

nagios nagios 3.0.6

nagios nagios 3.1.1

nagios nagios 3.2.2

nagios nagios 3.2.1

nagios nagios 3.2.0

Vendor Advisories

Debian Bug report logs - #629127 several XSS issues Package: nagios3; Maintainer for nagios3 is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Source for nagios3 is src:nagios3 (PTS, buildd, popcon) Reported by: "Thijs Kinkhorst" <thijs@debianorg> Date: Fri, 3 Jun 2011 18:15:01 UTC Seve ...
An attacker could modify or steal data if you were tricked into clicking on a special link to Nagios ...