Description
|
|
(#Several vulnerabilities were reported in Nagios XI:#- several cross-site scripting vulnerabilities located in the GET parameter "cmd" of the "includes/components/ccm/ajax.php" web page and in the POST parameter "svg" of the "includes/components/highcharts/exporting-server/index.php" web page##- content spoofing. A remote attacker could exploit it by setting a specially crafted "xiwindows" parameter of the "nagiosxi/admin/" web page in order to load content from a malicious URL into an IFRAME##- open redirect in the parameter "redirect" of the "nagiosxi/login.php" web page.##Updated, 20/10/2016:#Proofs of concept are available.)
|