5.4

CVE-2013-10074

Nagios XI < 2012R2.6 XSS via Tools Menu

Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NagiosNagios Xi Version < 2012
NagiosNagios Xi Version2012 Updater1.0
NagiosNagios Xi Version2012 Updater1.1
NagiosNagios Xi Version2012 Updater1.2
NagiosNagios Xi Version2012 Updater1.3
NagiosNagios Xi Version2012 Updater1.4
NagiosNagios Xi Version2012 Updater1.5
NagiosNagios Xi Version2012r1.6
NagiosNagios Xi Version2012r1.7
NagiosNagios Xi Version2012r1.8
NagiosNagios Xi Version2012r1.9
NagiosNagios Xi Version2012r2.0
NagiosNagios Xi Version2012r2.1
NagiosNagios Xi Version2012r2.2
NagiosNagios Xi Version2012r2.3
NagiosNagios Xi Version2012r2.4
NagiosNagios Xi Version2012r2.4 Updateb
NagiosNagios Xi Version2012r2.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.592
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
disclosure@vulncheck.com 5.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.