Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Centreon和Centreon Enterprise Server 代码注入漏洞
Vulnerability Description
Centreon(Merethis Centreon)是一套需要与Nagios搭配使用的开源IT监控软件。该软件通过网页(Web)管理Nagios,以及通过第三方组件实现对网络、操作系统和应用程序的监控。Centreon Enterprise Server(CES)是一个企业服务器版。 Centreon 2.5.1版本和Centreon Enterprise Server 2.2版本的displayServiceStatus.php脚本中存在代码注入漏洞,该漏洞源于程序没有充分过滤command_line
CVSS Information
N/A
Vulnerability Type
N/A