VYPR

Centreon

by Centreon

Source repositories

CVEs (130)

  • CVE-2019-15298HigNov 27, 2019
    risk 0.02cvss 8.8epss 0.27

    A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that…

  • CVE-2014-3829Oct 23, 2014
    risk 0.02cvss epss 0.81

    displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.

  • CVE-2014-3828Oct 23, 2014
    risk 0.02cvss epss 0.73

    Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.php, (2) the sid parameter…

  • CVE-2020-22345HigAug 18, 2021
    risk 0.00cvss 8.8epss 0.04

    /graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.

  • CVE-2021-37558CriAug 3, 2021
    risk 0.00cvss 9.8epss 0.02

    A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a…

  • CVE-2020-13252HigMay 21, 2020
    risk 0.00cvss 8.8epss 0.05

    Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.

  • CVE-2019-17647CriMar 5, 2020
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.

  • CVE-2019-17645HigMar 5, 2020
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/service/refreshMacroAjax.php.

  • CVE-2019-15299HigFeb 24, 2020
    risk 0.00cvss 8.8epss 0.02

    An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.

  • CVE-2019-15300HigNov 27, 2019
    risk 0.00cvss 8.8epss 0.02

    A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.

  • CVE-2018-21024CriOct 8, 2019
    risk 0.00cvss 9.8epss 0.02

    licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

  • CVE-2019-17108MedOct 8, 2019
    risk 0.00cvss 6.1epss 0.01

    Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.

  • CVE-2018-21023HigOct 8, 2019
    risk 0.00cvss 8.8epss 0.03

    getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.

  • CVE-2018-21022HigOct 8, 2019
    risk 0.00cvss 8.8epss 0.02

    makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.

  • CVE-2018-21021HigOct 8, 2019
    risk 0.00cvss 8.8epss 0.02

    img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.

  • CVE-2018-21020HigOct 8, 2019
    risk 0.00cvss 7.5epss 0.02

    In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.

  • CVE-2018-19312HigNov 16, 2018
    risk 0.00cvss 8.8epss 0.02

    Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.

  • CVE-2018-19311MedNov 16, 2018
    risk 0.00cvss 5.4epss 0.01

    Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.

  • CVE-2018-19281CriNov 14, 2018
    risk 0.00cvss 9.8epss 0.02

    Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.

  • CVE-2018-19280MedNov 14, 2018
    risk 0.00cvss 6.1epss 0.01

    Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.

Page 6 of 7