CVE-2011-2179
Nagios 3.2.3-Icinga <1.4.1 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Stefan Schurtz · textremotemultiple
https://www.exploit-db.com/exploits/35818
References (14)
Scores
EPSS
0.3006
EPSS Percentile
96.6%
Classification
CWE
CWE-79
Status
published
Affected Products (17)
icinga/icinga
< 1.4.0
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
icinga/icinga
... and 2 more
Timeline
Published
Jun 14, 2011
Tracked Since
Feb 18, 2026