Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Centreon Web 安全漏洞
Vulnerability Description
Centreon Web是法国Centreon公司的一套开源的系统监控工具 。该产品主要提供对网络、系统和应用程序等资源的监控功能。 Centreon Web 19.10.18版本, 20.04.8版本, 20.10.2版本存在安全漏洞,该漏洞源于不安全权限允许远程攻击者通过将任何文件扩展名更改为".gif",然后在应用程序的"管理参数图像"部分上传,从而绕过验证。
CVSS Information
N/A
Vulnerability Type
N/A