Описание
Command Injection in Centreon
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-13252
- https://github.com/centreon/centreon/pull/8467
- https://engindemirbilek.github.io/centreon-19.10-rce
- https://github.com/EnginDemirbilek/EnginDemirbilek.github.io/blob/master/centreon-19.10-rce.html
- https://github.com/centreon/centreon/compare/19.04.13...19.04.15
Пакеты
Наименование
centreon/centreon
composer
Затронутые версииВерсия исправления
< 19.04.15
19.04.15
Связанные уязвимости
CVSS3: 8.8
nvd
больше 5 лет назад
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.