vendor:
Oreon and Centreon
by:
Michael Brooks
N/A
CVSS
N/A
Multiple Remote File Inclusion
Unknown
CWE
Product Name: Oreon and Centreon
Affected Version From: 1.4
Affected Version To: 1.4.2001
Patch Exists: NO
Related CWE:
CPE: oreon:1.4, centreon:1.4.1
Platforms Tested:
2007
Multiple Remote File Inclusion in Oreon and Centreon
The vulnerability allows an attacker to include remote files in the vulnerable software. The vulnerable files in Oreon are './oreon-1.4/www/include/monitoring/engine/MakeXML.php' and './oreon-1.4/www/include/monitoring/engine/MakeXML4statusCounter.php'. The attack can be performed by appending a malicious URL to the vulnerable file. The exploit code is provided in the text.
Mitigation:
Unknown