mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 23:27:33 +02:00
874 B
874 B
CVE-2014-3829
Description
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.
POC
Reference
- http://seclists.org/fulldisclosure/2014/Oct/78
- http://seclists.org/fulldisclosure/2014/Oct/78
- http://www.kb.cert.org/vuls/id/298796
- http://www.kb.cert.org/vuls/id/298796
Github
No PoCs found on GitHub currently.