Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.
{
"binaries": [
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingacli"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.7.3-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.7.3-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.7.3-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.7.3-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.7.3-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.9.5-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.9.5-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.9.5-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.9.5-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.9.5-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.12.1-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.12.1-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.12.1-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.12.1-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.12.1-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.12.2-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.12.2-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.12.2-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.12.2-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.12.2-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.12.4-2",
"binary_name": "icingacli"
},
{
"binary_version": "2.12.4-2",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.12.4-2",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.12.4-2",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.12.4-2",
"binary_name": "php-icinga"
}
]
}