Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a custom main.php?p=60803&type=3 command. The user must then set the Pollers Post-Restart Command to this previously created command via the main.php?p=60901&o=c&server_id=1 URI. This is triggered via an export of the Poller Configuration.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Centreon Infrastructure Monitoring Software 安全漏洞
Vulnerability Description
Centreon(Merethis Centreon)是法国Centreon公司的一套开源的系统监控工具 。该产品主要提供对网络、系统和应用程序等资源的监控功能。 Centreon Infrastructure Monitoring Software 19.10及之前版本中存在安全漏洞。攻击者可借助Centreon Web Interface的管理员访问权限并创建自定义的main.php?p=60803&type=3命令利用该漏洞执行代码。
CVSS Information
N/A
Vulnerability Type
N/A