vendor:
Centreon
by:
Huy-Ngoc DAU of Deloitte Conseil, France
8.8
CVSS
HIGH
Unauthenticated Blind SQLi and Authenticated Remote Command Execution
89
CWE
Product Name: Centreon
Affected Version From: 2.5.2004
Affected Version To: 2.5.2004
Patch Exists: YES
Related CWE: CVE-2015-1560, CVE-2015-1561
CPE: a:merethis:centreon:2.5.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Merethis Centreon – Unauthenticated blind SQLi and Authenticated Remote Command Execution
Centron 2.5.4 is susceptible to multiple vulnerabilities, including unauthenticated blind SQL injection and authenticated remote system command execution. An attacker can exploit CVE-2015-1560 to obtain a valid session_id, which is required to exploit CVE-2015-1561. By exploiting CVE-2015-1561, an attacker can inject commands into the 'ns_id' and 'end' parameters, which are passed to the popen function.
Mitigation:
Update to Centreon version 2.5.5 or later.