6.1
CVSSv3

CVE-2016-6209

Published: 31/03/2017 Updated: 04/04/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Nagios.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nagios nagios -

Vendor Advisories

Debian Bug report logs - #831698 nagios3: CVE-2016-6209 Package: src:nagios3; Maintainer for src:nagios3 is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 18 Jul 2016 17:24:02 UTC Severity: important Tags: security, upstream ...
A user supplied GET parameter is used to create the value used as the src value of an iframe displayed on all pages It allows for CSRF and javascript insertion techniques among others An attacker could forge a malicious URL that could include javascript execution in the main browser frame context, force the target to view a malicious web page (c ...