LOW
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled, allow remote attackers to inject arbitrary web script or HTML via a JavaScript expression, as demonstrated by the onload attribute of a BODY element located after a check-host-alive! sequence, a different vulnerability than CVE-2011-2179
Published Jun 14, 2011
2.6
LOWCVSS 2.0
EPSS 0.87%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.