VDB

CVE-2014-3829

CVE-2014-3829 PUBLISHED CVSS 10 CRITICAL

displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.

EPSS 86.20% · 99.4th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
86.20%
99.4th percentile

Affected Products

VendorProductVersions
merethiscentreon2.5.1
n/an/an/a
merethiscentreon_enterprise_server2.2

Timeline

  • Oct 15, 2014 PoC Published
  • Oct 18, 2014 PoC Published
  • Oct 23, 2014 CVE Published
  • Oct 24, 2014 PoC Published
  • Mar 23, 2017 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›