Vulnerabilities > Centreon
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-05-27 | CVE-2020-10945 | Information Exposure vulnerability in Centreon and Widget-Host-Monitoring Centreon before 19.10.7 exposes Session IDs in server responses. | 4.3 |
2020-05-21 | CVE-2020-13252 | OS Command Injection vulnerability in Centreon Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page. | 8.8 |
2020-04-06 | CVE-2019-19699 | Improper Privilege Management vulnerability in Centreon There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. | 7.2 |
2020-03-20 | CVE-2019-19487 | OS Command Injection vulnerability in Centreon Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test. | 8.8 |
2020-03-20 | CVE-2019-19486 | Path Traversal vulnerability in Centreon Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test. | 6.5 |
2020-03-20 | CVE-2019-19484 | Open Redirect vulnerability in Centreon Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior. | 6.1 |
2020-03-05 | CVE-2019-17647 | SQL Injection vulnerability in Centreon An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. | 9.8 |
2020-03-05 | CVE-2019-17646 | Forced Browsing vulnerability in Centreon An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. | 7.5 |
2020-03-05 | CVE-2019-17645 | Forced Browsing vulnerability in Centreon An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. | 7.5 |
2020-03-05 | CVE-2019-17642 | OS Command Injection vulnerability in Centreon An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. | 8.8 |