Unrated severityNVD Advisory· Published Oct 23, 2014· Updated May 6, 2026
CVE-2014-3829
CVE-2014-3829
Description
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.
Affected products
2- cpe:2.3:a:merethis:centreon_enterprise_server:2.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- seclists.org/fulldisclosure/2014/Oct/78nvdExploit
- www.kb.cert.org/vuls/id/298796nvdThird Party AdvisoryUS Government Resource
- documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.5/centreon-2.5.3.htmlnvd
- github.com/centreon/centreon/commit/cc2109804dd69057cb209037113796ec5ffdce90nvd
News mentions
0No linked articles in our index yet.