mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
127 lines
4.5 KiB
JSON
127 lines
4.5 KiB
JSON
{
|
|
"CVE_data_meta": {
|
|
"ASSIGNER": "secalert@redhat.com",
|
|
"ID": "CVE-2011-2179",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "n/a",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "n/a"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"vendor_name": "n/a"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"data_format": "MITRE",
|
|
"data_type": "CVE",
|
|
"data_version": "4.0",
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action."
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "n/a"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"name": "20110601 Cross-Site Scripting vulnerability in Nagios",
|
|
"refsource": "BUGTRAQ",
|
|
"url": "http://archives.neohapsis.com/archives/bugtraq/2011-06/0018.html"
|
|
},
|
|
{
|
|
"name": "icinga-expand-xss(67797)",
|
|
"refsource": "XF",
|
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67797"
|
|
},
|
|
{
|
|
"name": "8274",
|
|
"refsource": "SREASON",
|
|
"url": "http://securityreason.com/securityalert/8274"
|
|
},
|
|
{
|
|
"name": "48087",
|
|
"refsource": "BID",
|
|
"url": "http://www.securityfocus.com/bid/48087"
|
|
},
|
|
{
|
|
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=709871",
|
|
"refsource": "CONFIRM",
|
|
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=709871"
|
|
},
|
|
{
|
|
"name": "http://tracker.nagios.org/view.php?id=224",
|
|
"refsource": "CONFIRM",
|
|
"url": "http://tracker.nagios.org/view.php?id=224"
|
|
},
|
|
{
|
|
"name": "[oss-security] 20110601 CVE request: XSS in nagios",
|
|
"refsource": "MLIST",
|
|
"url": "http://www.openwall.com/lists/oss-security/2011/06/01/10"
|
|
},
|
|
{
|
|
"name": "http://www.rul3z.de/advisories/SSCHADV2011-006.txt",
|
|
"refsource": "MISC",
|
|
"url": "http://www.rul3z.de/advisories/SSCHADV2011-006.txt"
|
|
},
|
|
{
|
|
"name": "[oss-security] 20110602 Re: CVE request: XSS in nagios",
|
|
"refsource": "MLIST",
|
|
"url": "http://www.openwall.com/lists/oss-security/2011/06/02/6"
|
|
},
|
|
{
|
|
"name": "https://dev.icinga.org/issues/1605",
|
|
"refsource": "CONFIRM",
|
|
"url": "https://dev.icinga.org/issues/1605"
|
|
},
|
|
{
|
|
"name": "44974",
|
|
"refsource": "SECUNIA",
|
|
"url": "http://secunia.com/advisories/44974"
|
|
},
|
|
{
|
|
"name": "http://www.rul3z.de/advisories/SSCHADV2011-005.txt",
|
|
"refsource": "MISC",
|
|
"url": "http://www.rul3z.de/advisories/SSCHADV2011-005.txt"
|
|
},
|
|
{
|
|
"name": "USN-1151-1",
|
|
"refsource": "UBUNTU",
|
|
"url": "http://www.ubuntu.com/usn/USN-1151-1"
|
|
},
|
|
{
|
|
"name": "20110601 Cross-Site Scripting vulnerability in Icinga",
|
|
"refsource": "BUGTRAQ",
|
|
"url": "http://archives.neohapsis.com/archives/bugtraq/2011-06/0017.html"
|
|
}
|
|
]
|
|
}
|
|
} |