VDB
CVE-2014-3828
CVE-2014-3828
PUBLISHED
CVSS 10 CRITICAL
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.php, (2) the sid parameter to views/graphs/GetXmlTree.php, (3) the session_id parameter to views/graphs/graphStatus/displayServiceStatus.php, (4) the mnftr_id parameter to configuration/configObject/traps/GetXMLTrapsForVendor.php, or (5) the index parameter to common/javascript/commandGetArgs/cmdGetExample.php in include/.
EPSS 78.59% · 99.1th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
78.59%
99.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| merethis | centreon_enterprise_server | 2.2 |
| merethis | centreon | 2.5.1 |
Timeline
- Oct 15, 2014 PoC Published
- Oct 18, 2014 PoC Published
- Oct 23, 2014 CVE Published
- Oct 24, 2014 PoC Published
- Oct 27, 2014 PoC Published
- Mar 23, 2017 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Aug 5, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
References
- http://www.kb.cert.org/vuls/id/298796 advisory
- 20141016 Multiple unauthenticated SQL injections and unauthenticated remote command injection in Centreon <= 2.5.2 and Centreon Enterprise Server <= 2.2|3.0 mailing-list
- 70648 vdb
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.5/centreon-2.5.3.html url
- https://github.com/centreon/centreon/commit/cc2109804dd69057cb209037113796ec5ffdce90#diff-e328097503b14fbb117e0db798aefcde url
- https://nvd.nist.gov/vuln/detail/CVE-2014-3828 advisory