CVE-2013-6039

Status: Deferred

CVSS Scores

CVSS v2 Base Score
4.3
MEDIUM

Description

Multiple cross-site scripting (XSS) vulnerabilities in NagiosQL 3.2 SP2 allow remote attackers to inject arbitrary web script or HTML via the txtSearch parameter to (1) admin/hostdependencies.php, (2) admin/hosts.php, or other unspecified pages that allow search input, related to the search functionality in functions/content_class.php.

Published
December 9, 2013 4:55 PM
Last Modified
April 11, 2025 12:51 AM
Source
[email protected]

Weaknesses (CWE)

CWE-79

References

Affected Configurations

[
    {
        "nodes": [
            {
                "operator": "OR",
                "negate": false,
                "cpeMatch": [
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:a:nagiosql:nagiosql:3.2:sp2:*:*:*:*:*:*",
                        "matchCriteriaId": "0FE5B2D4-971E-4702-B55E-28B06B65556B"
                    }
                ]
            }
        ]
    }
]

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.