EIP-2026-104347
PRE-CVENagios Log Server 2.1.6 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104347. PoCs published by Jinson Varghese Behanan.
AI-analyzed exploit summary This is a technical writeup detailing a stored XSS vulnerability in Nagios Log Server 2.1.6 and below. The vulnerability exists in the 'Full Name' and 'Username' fields on the profile or user creation pages, allowing an authenticated attacker to inject malicious JavaScript that executes when an admin views the alerts page.
Description
Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
Exploits (1)
This is a technical writeup detailing a stored XSS vulnerability in Nagios Log Server 2.1.6 and below. The vulnerability exists in the 'Full Name' and 'Username' fields on the profile or user creation pages, allowing an authenticated attacker to inject malicious JavaScript that executes when an admin views the alerts page.