Описание
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 19.04.0 (включая) до 19.04.15 (исключая)
cpe:2.3:a:centreon:centreon:*:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.0362
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78
Связанные уязвимости
EPSS
Процентиль: 87%
0.0362
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78