CVE-2011-10037: Nagios XI < 2011R1.9 XSS via xiwindow Variables Affecting Permalinks
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2011-10037?
CVE-2011-10037 is classified as a high-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2011-10037?
To fix CVE-2011-10037, upgrade Nagios XI to version 2011R1.9 or later.
What types of attacks can CVE-2011-10037 enable?
CVE-2011-10037 can enable attackers to perform cross-site scripting attacks, compromising user data.
Which versions of Nagios XI are affected by CVE-2011-10037?
CVE-2011-10037 affects all versions of Nagios XI prior to version 2011R1.9.
What components of Nagios XI does CVE-2011-10037 impact?
CVE-2011-10037 impacts the web interface of Nagios XI, specifically through the handling of xiwindow variables.