Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-38156 PoC — Nagios XI 跨站脚本漏洞

Source
Associated Vulnerability
Title:Nagios XI 跨站脚本漏洞 (CVE-2021-38156)
Description:Nagios XI是美国Nagios公司的一套IT基础设施监控解决方案。该方案支持对应用、服务、操作系统等进行监控和预警。 Nagios XI 存在跨站脚本漏洞,该漏洞源于在 5.8.6 版本之前的 Nagios XI 中,当管理员用户尝试编辑仪表板时,仪表板页面 /dashboards/# 中存在 XSS。
Description
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
File Snapshot

id: CVE-2021-38156 info: name: Nagios XI < 5.8.6 - Cross-Site Scripting author: ritikchaddha ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.