Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-2058
Description:Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page, or (2) remote authenticated users to inject arbitrary web script or HTML via an acknowledgement message, which is not properly handled in the "status" page.
Test IDs: 1.3.6.1.4.1.25623.1.0.703495   1.3.6.1.4.1.25623.1.1.1.2.2016.488  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-2058
Bugtraq: 20160214 Xymon: Critical security issues in all versions prior to 4.3.25 (Google Search)
http://www.securityfocus.com/archive/1/537522/100/0/threaded
Debian Security Information: DSA-3495 (Google Search)
http://www.debian.org/security/2016/dsa-3495
http://packetstormsecurity.com/files/135758/Xymon-4.3.x-Buffer-Overflow-Code-Execution-Information-Disclosure.html




© 1998-2025 E-Soft Inc. All rights reserved.