CVE-2018-18245
17.12.2018, 15:29
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
| Vendor | Product | Version |
|---|---|---|
| nagios | nagios_core | 4.4.2 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| nagios3 |
| ||||||||||||||||||||||||||||||
| nagios4 |
|
References