Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page, or (2) remote authenticated users to inject arbitrary web script or HTML via an acknowledgement message, which is not properly handled in the "status" page.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2016-04-13T16:00:00

Updated: 2018-10-09T18:57:01

Reserved: 2016-01-25T00:00:00


Link: CVE-2016-2058

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2016-04-13T16:59:08.787

Modified: 2018-10-09T19:59:33.850


Link: CVE-2016-2058

JSON object: View

cve-icon Redhat Information

No data.

CWE