Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.4.1-1ubuntu0.1" }, { "binary_name": "icingaweb2", "binary_version": "2.4.1-1ubuntu0.1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.4.1-1ubuntu0.1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.4.1-1ubuntu0.1" }, { "binary_name": "php-icinga", "binary_version": "2.4.1-1ubuntu0.1" } ] }
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.7.3-1" }, { "binary_name": "icingaweb2", "binary_version": "2.7.3-1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.7.3-1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.7.3-1" }, { "binary_name": "php-icinga", "binary_version": "2.7.3-1" } ] }
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.9.5-1" }, { "binary_name": "icingaweb2", "binary_version": "2.9.5-1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.9.5-1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.9.5-1" }, { "binary_name": "php-icinga", "binary_version": "2.9.5-1" } ] }
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.12.1-1" }, { "binary_name": "icingaweb2", "binary_version": "2.12.1-1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.12.1-1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.12.1-1" }, { "binary_name": "php-icinga", "binary_version": "2.12.1-1" } ] }
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.12.2-1" }, { "binary_name": "icingaweb2", "binary_version": "2.12.2-1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.12.2-1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.12.2-1" }, { "binary_name": "php-icinga", "binary_version": "2.12.2-1" } ] }