Vulnerabilities > Centreon > Centreon > 2.99.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-04-06 | CVE-2019-19699 | Improper Privilege Management vulnerability in Centreon There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. | 7.2 |
2020-03-20 | CVE-2019-19487 | OS Command Injection vulnerability in Centreon Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test. | 8.8 |
2020-03-20 | CVE-2019-19486 | Path Traversal vulnerability in Centreon Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test. | 6.5 |
2020-03-20 | CVE-2019-19484 | Open Redirect vulnerability in Centreon Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior. | 6.1 |
2020-03-04 | CVE-2019-17644 | Forced Browsing vulnerability in Centreon An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. | 7.5 |
2020-03-04 | CVE-2019-17643 | Forced Browsing vulnerability in Centreon An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. | 7.5 |
2020-01-16 | CVE-2019-20327 | Incorrect Permission Assignment for Critical Resource vulnerability in Centreon Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. | 7.8 |
2019-09-25 | CVE-2019-16194 | SQL Injection vulnerability in Centreon SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php. | 9.8 |