Advisory: Cross-Site Scripting vulnerabilities in Icinga Advisory ID: SSCHADV2011-001 Author: Stefan Schurtz Affected Software: Successfully tested on: icinga-1.3.0 / icinga-1.2.1 Vendor URL: http://www.icinga.org Vendor Status: fixed csv export link to make it XSS save (IE) #1275 CVE-ID: - ========================== Vulnerability Description: ========================== This is Cross-Site Scripting vulnerability ================== Technical Details: ================== No input validation for "QUERY_STRING" Problem in "status.c" http://site/icinga/cgi-bin/status.cgi?' http://site/icinga/cgi-bin/status.cgi?'Export to CSVn",STATUS_CGI,strdup(getenv("QUERY_STRING"))); } else { printf("