Multiple cross-site scripting (XSS) vulnerabilities in CGI programs in Nagios before 2.12 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-5624 and CVE-2008-1360.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade nagiosUpgrade nagios-devel | Dec 10, 2025 | May 28, 2008 |
| Suse | — | Upgrade nagios-wwwUpgrade nagios-develUpgrade nagios | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade nagios3Upgrade nagios2 | Nov 19, 2024 | May 13, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub