CVE-2014-4907

Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.
Configurations

Configuration 1 (hide)

cpe:2.3:a:op5:monitor:6.3.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:pnp4nagios:pnp4nagios:*:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.0:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.3:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.4:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.5:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.6:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.7:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.10:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.11:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.12:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.13:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.14:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.15:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.16:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.17:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.18:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.19:*:*:*:*:*:*:*
cpe:2.3:a:pnp4nagios:pnp4nagios:0.6.20:*:*:*:*:*:*:*

History

21 Nov 2024, 02:11

Type Values Removed Values Added
References () http://docs.pnp4nagios.org/pnp-0.6/dwnld - Patch () http://docs.pnp4nagios.org/pnp-0.6/dwnld - Patch
References () http://openwall.com/lists/oss-security/2014/07/11/3 - () http://openwall.com/lists/oss-security/2014/07/11/3 -
References () http://secunia.com/advisories/59535 - () http://secunia.com/advisories/59535 -
References () http://secunia.com/advisories/59603 - () http://secunia.com/advisories/59603 -
References () http://sourceforge.net/p/pnp4nagios/code/ci/f846a6c9d007ca2bee05359af747619151195fc9 - Exploit, Patch () http://sourceforge.net/p/pnp4nagios/code/ci/f846a6c9d007ca2bee05359af747619151195fc9 - Exploit, Patch
References () http://www.op5.com/blog/news/op5-monitor-6-3-1-release-notes - Vendor Advisory () http://www.op5.com/blog/news/op5-monitor-6-3-1-release-notes - Vendor Advisory
References () http://www.securityfocus.com/bid/68350 - () http://www.securityfocus.com/bid/68350 -
References () https://bugs.op5.com/view.php?id=8761 - () https://bugs.op5.com/view.php?id=8761 -

Information

Published : 2014-07-11 11:08

Updated : 2024-11-21 02:11


NVD link : CVE-2014-4907

Mitre link : CVE-2014-4907

CVE.ORG link : CVE-2014-4907


JSON object : View

Products Affected

pnp4nagios

  • pnp4nagios

op5

  • monitor
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')