CVE-2014-4908: XSS
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohanaerrorpage.php or (2) share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4908?
CVE-2014-4908 is classified as a medium-severity vulnerability due to its potential for enabling cross-site scripting attacks.
How do I fix CVE-2014-4908?
To address CVE-2014-4908, upgrade PNP4Nagios to version 0.6.22 or later where the vulnerabilities have been patched.
What are the risks associated with CVE-2014-4908?
Exploitation of CVE-2014-4908 can allow remote attackers to inject malicious scripts, leading to unauthorized actions or data exposure.
Which versions of PNP4Nagios are affected by CVE-2014-4908?
CVE-2014-4908 affects PNP4Nagios versions up to and including 0.6.21.
Can CVE-2014-4908 be exploited in a low-security environment?
Yes, CVE-2014-4908 can be exploited even in low-security environments, as it does not require high-level access to initiate an attack.