MGASA-2015-0203

Source
https://advisories.mageia.org/MGASA-2015-0203.html
Import Source
https://advisories.mageia.org/MGASA-2015-0203.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0203
Upstream
  • CVE-2014-4907
  • CVE-2014-4908
Published
2015-05-11T20:10:38Z
Modified
2026-04-16T06:23:09Z
Summary
Updated pnp4nagios packages fix security vulnerabilities
Details

Updated pnp4nagios package fixes security vulnerabilities:

Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message (CVE-2014-4907).

Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching share/pnp/application/views/kohana_error_page.php or share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element (CVE-2014-4908).

References
Credits

Affected packages

Mageia:4 / pnp4nagios

Package

Name
pnp4nagios
Purl
pkg:rpm/mageia/pnp4nagios?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.6.25-1.1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0203.json"