Release date: 2010-09-17
Updated on: 2010-09-20
Affected Systems:
Nagios XI 2009 R1.3B
Unaffected system:
Nagios XI 2009 R1.3C
Description:
--------------------------------------------------------------------------------
Nagios is a free open-source host and service monitoring software that can be used in a variety of Linux and Unix operating systems.
The supported des/utils of Nagios. inc. the grab_request_var () function in the PHP file does not properly filter the information that the user submits to admin/users. parameters such as sortby, sortorder, search, records, and page on the php page are returned to the user. Remote attackers can execute cross-site scripting attacks by submitting malicious parameter requests.
<* Source: Secunia
Link: http://secunia.com/secunia_research/2010-115/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Nagios
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.nagios.org/