CVE-2011-2179
Last modified
CVE-2011-2179 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.. EPSS estimates a 26.04% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Icinga | Icinga | <= 1.4.0 |
| Icinga | Icinga | 0.8.0 |
| Icinga | Icinga | 0.8.1 |
| Icinga | Icinga | 0.8.2 |
| Icinga | Icinga | 0.8.3 |
| Icinga | Icinga | 0.8.4 |
| Icinga | Icinga | 1.0 |
| Icinga | Icinga | 1.0.1 |
| Icinga | Icinga | 1.0.2 |
| Icinga | Icinga | 1.0.3 |
| Icinga | Icinga | 1.2.0 |
| Icinga | Icinga | 1.2.1 |
| Icinga | Icinga | 1.3.0 |
| Icinga | Icinga | 1.3.1 |
| Nagios | Nagios | 3.2.3 |
References
- http://tracker.nagios.org/view.php?id=224Exploit, Patch, Vendor Advisory
- http://www.rul3z.de/advisories/SSCHADV2011-005.txtExploit, Patch
- http://www.rul3z.de/advisories/SSCHADV2011-006.txtExploit, Patch
- https://dev.icinga.org/issues/1605Exploit, Patch, Vendor Advisory
- http://tracker.nagios.org/view.php?id=224Exploit, Patch, Vendor Advisory
- http://www.rul3z.de/advisories/SSCHADV2011-005.txtExploit, Patch
- http://www.rul3z.de/advisories/SSCHADV2011-006.txtExploit, Patch
- https://dev.icinga.org/issues/1605Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-2179?
How severe is CVE-2011-2179?
How do I fix CVE-2011-2179?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-2173The implementation of OutputMediator objects in IBM WebSpher…
- CVE-2011-2174Double free vulnerability in the tvb_uncompress function in …
- CVE-2011-2175Integer underflow in the visual_read function in wiretap/vis…
- CVE-2011-2176GNOME NetworkManager before 0.8.6 does not properly enforce …
- CVE-2011-2177OpenOffice.org v3.3 allows execution of arbitrary code with …7.8
- CVE-2011-2178The virSecurityManagerGetPrivateData function in security/se…
- CVE-2011-2180Cross-site scripting (XSS) vulnerability in dereferer.php in…
- CVE-2011-2181Multiple SQL injection vulnerabilities in A Really Simple Ch…
- CVE-2011-2182The ldm_frag_add function in fs/partitions/ldm.c in the Linu…
- CVE-2011-2183Race condition in the scan_get_next_rmap_item function in mm…
- CVE-2011-2184The key_replace_session_keyring function in security/keys/pr…
- CVE-2011-2185Fabric before 1.1.0 allows local users to overwrite arbitrar…
Are you affected by CVE-2011-2179?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
