CVE-2011-2477

CVSS 2.6 - LOW
Description

Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled, allow remote attackers to inject arbitrary web script or HTML via a JavaScript expression, as demonstrated by the onload attribute of a BODY element located after a check-host-alive! sequence, a different vulnerability than CVE-2011-2179.

Affected Products
15
Vendor Product Version
icinga icinga All versions
icinga icinga 0.8.0
icinga icinga 0.8.1
icinga icinga 0.8.2
icinga icinga 0.8.3
icinga icinga 0.8.4
icinga icinga 1.0
icinga icinga 1.0
icinga icinga 1.0.1
icinga icinga 1.0.2
icinga icinga 1.0.3
icinga icinga 1.2.0
icinga icinga 1.2.1
icinga icinga 1.3.0
icinga icinga 1.3.1
Weakness Types
CWE-79
CVE Information
CVE ID:
CVE-2011-2477
Published:
2011-06-14
Modified:
2026-04-29
CVSS Score:
2.6
Severity:
LOW
Vector:
AV:N/AC:H/Au:N/C:N/I:P/A:N
Affected Vendors
icinga
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL