Vulnerability Name: | CVE-2014-4907 (CCN-94240) | ||||||||||||
Assigned: | 2014-07-03 | ||||||||||||
Published: | 2014-07-03 | ||||||||||||
Updated: | 2014-07-17 | ||||||||||||
Summary: | Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:TF/RC:C)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:TF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-4907 Source: CONFIRM Type: Patch http://docs.pnp4nagios.org/pnp-0.6/dwnld Source: MLIST Type: UNKNOWN [oss-security] 20140711 Re: CVE request: XSS in PNP4Nagios Source: CCN Type: oss-security Mailing List, Thu, 3 Jul 2014 15:13:49 +0200 CVE request: pnp4nagios - Two URL Cross-Site Scripting Vulnerabilities Source: SECUNIA Type: UNKNOWN 59535 Source: SECUNIA Type: UNKNOWN 59603 Source: CONFIRM Type: Exploit, Patch http://sourceforge.net/p/pnp4nagios/code/ci/f846a6c9d007ca2bee05359af747619151195fc9 Source: CONFIRM Type: Vendor Advisory http://www.op5.com/blog/news/op5-monitor-6-3-1-release-notes Source: CCN Type: OSVDB ID: 108638 PNP4Nagios application/views/kohana_error_page.php Meta Refresh Request URI Handling Reflected XSS Source: CCN Type: PNP4Nagios Web site PNP4Nagios Source: BID Type: UNKNOWN 68350 Source: CCN Type: BID-68350 PNP4Nagios 'kohana_error_page.php' Cross Site Scripting Vulnerability Source: CONFIRM Type: UNKNOWN https://bugs.op5.com/view.php?id=8761 Source: XF Type: UNKNOWN pnp4nagios-kohanaerrorpage-xss(94240) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |