Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8010

Опубликовано: 27 мар. 2017
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icingafixed1.13.3-3package
icingano-dsajessiepackage
icingano-dsawheezypackage
icinganot-affectedsqueezepackage

Примечания

  • Introduced by: https://dev.icinga.org/issues/593 in 1.3.

  • Upstream issue: https://dev.icinga.org/issues/10453

  • Upstream fix: https://dev.icinga.org/projects/icinga-core/repository/revisions/5c816f5d9352c373e9dadb95b63612a96cf96dff

  • https://www.openwall.com/lists/oss-security/2015/10/23/15

EPSS

Процентиль: 71%
0.01486
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.

CVSS3: 6.1
nvd
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.

CVSS3: 6.1
github
больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.

suse-cvrf
больше 9 лет назад

Security update for icinga

suse-cvrf
почти 8 лет назад

Security update for icinga

EPSS

Процентиль: 71%
0.01486
Низкий