Executive Summary
This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations | |||
---|---|---|---|
Name | CVE-2008-1360 | First vendor Publication | 2008-03-17 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Cross-site scripting (XSS) vulnerability in Nagios before 2.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts, a different issue than CVE-2007-5624. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1360 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13118 | |||
Oval ID: | oval:org.mitre.oval:def:13118 | ||
Title: | DSA-1883-2 nagios2 -- missing input sanitising | ||
Description: | The previous nagios2 update introduced a regression, which caused status.cgi to segfault when used directly without specifying the "host" variable. This update fixes the problem. For reference the original advisory text follows. Several vulnerabilities have been found in nagios2, ahost/service/network monitoring and management system. The Common Vulnerabilities and Exposures project identifies the following problems: Several cross-site scripting issues via several parameters were discovered in the CGI scripts, allowing attackers to inject arbitrary HTML code. In order to cover the different attack vectors, these issues have been assigned CVE-2007-5624, CVE-2007-5803 and CVE-2008-1360. For the oldstable distribution, these problems have been fixed in version 2.6-2+etch5. The stable distribution does not include nagios2 and nagios3 is not affected by these problems. The testing distribution and the unstable distribution do not contain nagios2 and nagios3 is not affected by these problems. We recommend that you upgrade your nagios2 packages. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1883-2 CVE-2007-5624 CVE-2007-5803 CVE-2008-1360 | Version: | 5 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | nagios2 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:13703 | |||
Oval ID: | oval:org.mitre.oval:def:13703 | ||
Title: | DSA-1883-1 nagios2 -- missing input sanitising | ||
Description: | Several vulnerabilities have been found in nagios2, ahost/service/network monitoring and management system. The Common Vulnerabilities and Exposures project identifies the following problems: Several cross-site scripting issues via several parameters were discovered in the CGI scripts, allowing attackers to inject arbitrary HTML code. In order to cover the different attack vectors, these issues have been assigned CVE-2007-5624, CVE-2007-5803 and CVE-2008-1360. For the oldstable distribution, these problems have been fixed in version 2.6-2+etch4. The stable distribution does not include nagios2 and nagios3 is not affected by these problems. The testing distribution and the unstable distribution do not contain nagios2 and nagios3 is not affected by these problems. We recommend that you upgrade your nagios2 packages. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1883-1 CVE-2007-5624 CVE-2007-5803 CVE-2008-1360 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | nagios2 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:7884 | |||
Oval ID: | oval:org.mitre.oval:def:7884 | ||
Title: | DSA-1883 nagios2 -- missing input sanitising | ||
Description: | Several vulnerabilities have been found in nagios2, a host/service/network monitoring and management system. The Common Vulnerabilities and Exposures project identifies the following problems: Several cross-site scripting issues via several parameters were discovered in the CGI scripts, allowing attackers to inject arbitrary HTML code. In order to cover the different attack vectors, these issues have been assigned CVE-2008-1360. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1883 CVE-2007-5624 CVE-2007-5803 CVE-2008-1360 | Version: | 3 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | nagios2 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 7 |
OpenVAS Exploits
Date | Description |
---|---|
2009-10-13 | Name : SLES10: Security update for nagios File : nvt/sles10_nagios0.nasl |
2009-09-15 | Name : Debian Security Advisory DSA 1883-1 (nagios2) File : nvt/deb_1883_1.nasl |
2009-09-15 | Name : Debian Security Advisory DSA 1883-2 (nagios2) File : nvt/deb_1883_2.nasl |
2009-06-05 | Name : Ubuntu USN-723-1 (git-core) File : nvt/ubuntu_723_1.nasl |
2009-03-02 | Name : Mandrake Security Advisory MDVSA-2009:054 (nagios) File : nvt/mdksa_2009_054.nasl |
2008-09-04 | Name : FreeBSD Ports: nagios File : nvt/freebsd_nagios.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
42951 | Nagios Unspecified XSS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-02-24 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1883.nasl - Type : ACT_GATHER_INFO |
2008-05-01 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_nagios-5165.nasl - Type : ACT_GATHER_INFO |
2008-05-01 | Name : The remote openSUSE host is missing a security update. File : suse_nagios-5168.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:14:49 |
|
2024-11-28 12:15:12 |
|
2021-05-04 12:07:18 |
|
2021-04-22 01:07:42 |
|
2020-05-23 00:21:27 |
|
2017-08-08 09:23:57 |
|
2016-04-26 17:14:04 |
|
2014-02-17 10:44:16 |
|
2013-05-11 00:12:34 |
|