CVE-2011-2179

Nagios 3.2.3-Icinga <1.4.1 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stefan Schurtz · textremotemultiple
https://www.exploit-db.com/exploits/35818

Scores

EPSS 0.3006
EPSS Percentile 96.6%

Classification

CWE
CWE-79
Status published

Affected Products (17)

icinga/icinga < 1.4.0
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
... and 2 more

Timeline

Published Jun 14, 2011
Tracked Since Feb 18, 2026