VYPR

Vendor CVEs

Centreon

All CVEs

139 total · sorted by risk
  • CVE-2020-10945MedMay 27, 2020
    risk 0.21cvss 4.3epss 0.01

    Centreon before 19.10.7 exposes Session IDs in server responses.

  • CVE-2019-13024HigJul 1, 2019
    risk 0.06cvss 8.8epss 0.32

    Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it…

  • CVE-2008-1119Mar 3, 2008
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter.

  • CVE-2007-6485Dec 20, 2007
    risk 0.04cvss epss 0.11

    Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.

  • CVE-2011-4431Nov 10, 2011
    risk 0.03cvss epss 0.06

    Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter.

  • CVE-2010-1301Apr 7, 2010
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parameter.

  • CVE-2008-1178Mar 6, 2008
    risk 0.03cvss epss 0.05

    Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119.

  • CVE-2021-37556HigAug 3, 2021
    risk 0.02cvss 8.8epss 0.27

    A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end…

  • CVE-2019-15298HigNov 27, 2019
    risk 0.02cvss 8.8epss 0.27

    A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that…

  • CVE-2014-3829Oct 23, 2014
    risk 0.02cvss epss 0.81

    displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.

  • CVE-2014-3828Oct 23, 2014
    risk 0.02cvss epss 0.73

    Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.php, (2) the sid parameter…

  • CVE-2020-22345HigAug 18, 2021
    risk 0.00cvss 8.8epss 0.04

    /graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.

  • CVE-2021-37558CriAug 3, 2021
    risk 0.00cvss 9.8epss 0.02

    A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a…

  • CVE-2020-13252HigMay 21, 2020
    risk 0.00cvss 8.8epss 0.05

    Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.

  • CVE-2019-17647CriMar 5, 2020
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.

  • CVE-2019-17645HigMar 5, 2020
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/service/refreshMacroAjax.php.

  • CVE-2019-15299HigFeb 24, 2020
    risk 0.00cvss 8.8epss 0.02

    An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.

  • CVE-2019-15300HigNov 27, 2019
    risk 0.00cvss 8.8epss 0.02

    A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.

  • CVE-2018-21024CriOct 8, 2019
    risk 0.00cvss 9.8epss 0.02

    licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

  • CVE-2019-17108MedOct 8, 2019
    risk 0.00cvss 6.1epss 0.01

    Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.

  • CVE-2019-17106MedOct 8, 2019
    risk 0.00cvss 6.5epss 0.01

    In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.

  • CVE-2018-21023HigOct 8, 2019
    risk 0.00cvss 8.8epss 0.03

    getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.

  • CVE-2018-21022HigOct 8, 2019
    risk 0.00cvss 8.8epss 0.02

    makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.

  • CVE-2018-21021HigOct 8, 2019
    risk 0.00cvss 8.8epss 0.02

    img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.

  • CVE-2018-21020HigOct 8, 2019
    risk 0.00cvss 7.5epss 0.02

    In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.

  • CVE-2018-19312HigNov 16, 2018
    risk 0.00cvss 8.8epss 0.02

    Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.

  • CVE-2018-19311MedNov 16, 2018
    risk 0.00cvss 5.4epss 0.01

    Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.

  • CVE-2018-19281CriNov 14, 2018
    risk 0.00cvss 9.8epss 0.02

    Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.

  • CVE-2018-19280MedNov 14, 2018
    risk 0.00cvss 6.1epss 0.01

    Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.

  • CVE-2018-19271HigNov 14, 2018
    risk 0.00cvss 8.8epss 0.02

    Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.

  • CVE-2018-11589CriJun 25, 2018
    risk 0.00cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in…

  • CVE-2018-11588MedJun 25, 2018
    risk 0.00cvss 5.4epss 0.01

    Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArgu…

  • CVE-2018-11587CriJun 25, 2018
    risk 0.00cvss 9.8epss 0.04

    There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.

  • CVE-2015-1561Jul 14, 2015
    risk 0.00cvss epss 0.09

    The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands…

  • CVE-2015-1560Jul 14, 2015
    risk 0.00cvss epss 0.07

    SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to…

  • CVE-2012-5967Dec 19, 2012
    risk 0.00cvss epss 0.03

    SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execute arbitrary SQL commands via the menu parameter.

  • CVE-2011-4432Nov 10, 2011
    risk 0.00cvss epss 0.01

    www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.

  • CVE-2009-4368Dec 21, 2009
    risk 0.00cvss epss 0.03

    Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute tool, and (3) ldap import, possibly related to improper authentication.

  • CVE-2008-1179Mar 6, 2008
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) title parameters. NOTE: some of these details are obtained…

Page 3 of 3