Vulnerabilities
Vulnerable Software
Centreon:  >> Centreon  Security Vulnerabilities
Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Commands > Discovery screen). CVE-2019-17501 and CVE-2019-16405 are similar to one another and may be the same.
CVSS Score
8.8
EPSS Score
0.006
Published
2019-10-14
licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
CVSS Score
9.8
EPSS Score
0.003
Published
2019-10-08
SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.
CVSS Score
9.8
EPSS Score
0.002
Published
2019-09-25
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).
CVSS Score
8.8
EPSS Score
0.651
Published
2019-07-01
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
CVSS Score
5.4
EPSS Score
0.001
Published
2018-11-16
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.
CVSS Score
8.8
EPSS Score
0.002
Published
2018-11-16
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
CVSS Score
6.1
EPSS Score
0.001
Published
2018-11-14
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
CVSS Score
9.8
EPSS Score
0.002
Published
2018-11-14
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.
CVSS Score
8.8
EPSS Score
0.003
Published
2018-11-14
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.
CVSS Score
9.8
EPSS Score
0.011
Published
2018-06-25


Contact Us

Shodan ® - All rights reserved