Cross-site scripting (XSS) vulnerability in statusmap.c in statusmap.cgi in Nagios 3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the layer parameter.
https://bugzilla.redhat.com/show_bug.cgi?id=690877
http://www.ubuntu.com/usn/USN-1151-1
http://securityreason.com/securityalert/8241
http://secunia.com/advisories/44974
http://secunia.com/advisories/43287