High severity8.8NVD Advisory· Published May 21, 2020· Updated Jun 17, 2026
CVE-2020-13252
CVE-2020-13252
Description
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
centreon/centreonPackagist | < 19.04.15 | 19.04.15 |
Affected products
3- Centreon/Centreondescription
Patches
Vulnerability mechanics
References
6- github.com/centreon/centreon/compare/19.04.13...19.04.15nvdPatchThird Party AdvisoryWEB
- github.com/centreon/centreon/pull/8467nvdPatchThird Party AdvisoryWEB
- engindemirbilek.github.io/centreon-19.10-rcenvdExploitThird Party AdvisoryWEB
- github.com/EnginDemirbilek/EnginDemirbilek.github.io/blob/master/centreon-19.10-rce.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-jmgg-wx67-7qfvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-13252ghsaADVISORY
News mentions
0No linked articles in our index yet.