Candidate: CVE-2016-2058 PublicDate: 2016-04-13 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2058 http://lists.xymon.com/pipermail/xymon/2016-February/042986.html Description: Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page, or (2) remote authenticated users to inject arbitrary web script or HTML via an acknowledgement message, which is not properly handled in the "status" page. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Markus Krell Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N [5.4 MEDIUM] Patches_xymon: upstream_xymon: released (4.3.25-1) precise_xymon: ignored (reached end-of-life) precise/esm_xymon: DNE (precise was needs-triage) trusty_xymon: ignored (reached end-of-life) trusty/esm_xymon: DNE (trusty was needed) vivid/stable-phone-overlay_xymon: DNE vivid/ubuntu-core_xymon: DNE wily_xymon: ignored (reached end-of-life) xenial_xymon: not-affected (4.3.25-1) yakkety_xymon: not-affected (4.3.25-1) zesty_xymon: not-affected (4.3.25-1) artful_xymon: not-affected (4.3.25-1) bionic_xymon: not-affected (4.3.25-1) cosmic_xymon: not-affected (4.3.25-1) disco_xymon: not-affected (4.3.25-1) devel_xymon: not-affected (4.3.25-1)