Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1360 to the following vulnerability: Cross-site scripting (XSS) vulnerability in Nagios before 2.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts, a different issue than CVE-2007-5624. References: http://www.nagios.org/development/changelog.php#2x_branch http://www.securityfocus.com/bid/28250 http://secunia.com/advisories/29363
Created attachment 305353 [details] SuSE patch This fix is present in the upstream version 2.11. (Extracted from SuSE nagios-2.9-48.4.src.rpm)
Reporter changed to security-response-team by request of Jay Turner.
HPC and EPEL4/5 have 2.12 so aren't affected by this, and Fedora has much newer versions.