CVE-2008-1360: XSS
Cross-site scripting (XSS) vulnerability in Nagios before 2.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts, a different issue than CVE-2007-5624.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1360?
CVE-2008-1360 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2008-1360?
To fix CVE-2008-1360, upgrade Nagios to version 2.11 or later, which addresses this security issue.
What types of attacks does CVE-2008-1360 enable?
CVE-2008-1360 allows attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Which versions of Nagios are affected by CVE-2008-1360?
CVE-2008-1360 affects several versions of Nagios prior to 2.11, including versions 2.2, 2.3, 2.7, 2.8, and 2.9.
Is there a workaround for CVE-2008-1360 if I cannot upgrade?
There is no official workaround for CVE-2008-1360; upgrading to a secure version is the recommended mitigation.