CVE-2011-10040: Nagios XI < 2011R1.9 XSS via Status/Report Page Link Functions
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2011-10040?
CVE-2011-10040 has a medium severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-10040?
To fix CVE-2011-10040, you should upgrade Nagios XI to version 2011R1.9 or later.
What type of vulnerability is CVE-2011-10040?
CVE-2011-10040 is a cross-site scripting (XSS) vulnerability that allows for arbitrary script injection via user input.
What software is affected by CVE-2011-10040?
CVE-2011-10040 affects Nagios XI versions prior to 2011R1.9.
Can CVE-2011-10040 be exploited remotely?
Yes, CVE-2011-10040 can potentially be exploited remotely due to the nature of the XSS vulnerability.