Centreon

Centreon

70 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 25.06.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:40

Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve par...

  • EPSS 1.08%
  • Veröffentlicht 25.06.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:40

There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.

  • EPSS 0.07%
  • Veröffentlicht 25.06.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:40

Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 07.09.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).

Exploit
  • EPSS 5.24%
  • Veröffentlicht 14.07.2015 16:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to...

Exploit
  • EPSS 2.98%
  • Veröffentlicht 14.07.2015 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid p...

  • EPSS 0.05%
  • Veröffentlicht 06.03.2008 00:44:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) title parameters. NOTE: some of ...

  • EPSS 0.83%
  • Veröffentlicht 06.03.2008 00:44:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119.

  • EPSS 0.61%
  • Veröffentlicht 03.03.2008 22:44:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter.

Exploit
  • EPSS 1.21%
  • Veröffentlicht 20.12.2007 20:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitori...