CVE Database
/

CVE-2017-11507

Back to search

CVE-2017-11507

Published: Dec 11, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an unauthenticated attacker to inject arbitrary HTML or JavaScript via the output_format parameter, and the username parameter of failed HTTP basic authentication attempts, which is returned unencoded in an internal server error page.

VendorProductVersions

Tenable

Check_MK

affected
1.2.8x prior to 1. 2.8p25
affected
1.4.0x prior to 1.4.0p9

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now