Improper input validation in Nagios Fusion 4.1.8 and previous versions allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.
nagios fusion