REDHAT-BUG-690877: XSS
Cross-site scripting (XSS) vulnerability in Nagios allows remote attackers to inject arbitrary web script or HTML via specially-crafted 'layer' parameter passed to the Nagios network status map CGI script (statusmap.cgi).
References: [1] http://tracker.nagios.org/view.php?id=207 [2] http://www.rul3z.de/advisories/SSCHADV2011-002.txt [3] http://secunia.com/advisories/43287/
Public PoC (from [2): ===================== http://site/nagios/cgi-bin/statusmap.cgi?layer=' onmouseover="alert('XSS')" '
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-690877?
The severity of REDHAT-BUG-690877 is considered high due to the potential for remote attackers to exploit the XSS vulnerability.
How do I fix REDHAT-BUG-690877?
To fix REDHAT-BUG-690877, upgrade Nagios to the latest version that addresses the Cross-site scripting vulnerability.
What systems are affected by REDHAT-BUG-690877?
The systems affected by REDHAT-BUG-690877 include installations of Nagios that utilize the network status map CGI script.
What type of vulnerability is REDHAT-BUG-690877?
REDHAT-BUG-690877 is a Cross-site scripting (XSS) vulnerability.
What can attackers achieve with REDHAT-BUG-690877?
Attackers can use REDHAT-BUG-690877 to inject arbitrary web scripts or HTML into the Nagios web interface.