Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Nagios Log Server < 2.1.6 XSS via Create User, Edit User, & Manage Host Lists Pages
Vulnerability Description
Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Nagios Log Server 安全漏洞
Vulnerability Description
Nagios Log Server是美国Nagios公司的一套集中式日志管理、监控和分析软件。 Nagios Log Server 2.1.6之前版本存在安全漏洞,该漏洞源于web界面中创建用户、编辑用户和管理主机列表页面未充分验证或转义用户输入,可能导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A