📦

centreon

Vendor: centreon

Actively Exploited 0 CISA KEV List
PoC / Exploits 7 Code Available
Total RCEs 12 Remote Access
Total CVEs 90 Total Indexed
Avg. EPSS 10.74% Exploit Prob.
Latest CVE CVE-2024-39843 Sep 23

Security Vulnerability Index

Page 6 / 9
5.4 CVSS

Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArguments.php.

EPSS: 1.11%
9.8 CVSS

There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.

EPSS: 4.25%
5.4 CVSS

Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).

EPSS: 1.32%
6.5 CVSS
CVE-2015-1561
RCE Exploit Found

The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.

EPSS: 9.15%
7.5 CVSS
CVE-2015-1560
Exploit Found

SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to include/common/XmlTree/GetXmlTree.php.

EPSS: 6.69%
4.3 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) title parameters. NOTE: some of these details are obtained from third party information.

EPSS: 1.64%
4.3 CVSS
CVE-2008-1178
Exploit Found

Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119.

EPSS: 5.20%
5.0 CVSS
CVE-2008-1119
Exploit Found

Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter.

EPSS: 8.10%
7.5 CVSS
CVE-2007-6485
RCE Exploit Found

Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.

EPSS: 10.81%