CVE-2024-23115 – Centreon updateGroups SQL Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-23115
09 Feb 2024 — Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateGroups function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. • https://www.zerodayinitiative.com/advisories/ZDI-24-117 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-23116 – Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-23116
09 Feb 2024 — Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateLCARelation function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. • https://github.com/zgimszhd61/CVE-2024-23116 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-23117 – Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-23117
09 Feb 2024 — Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateContactServiceCommands function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. • https://github.com/zgimszhd61/CVE-2024-23117 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-23118 – Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-23118
09 Feb 2024 — Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateContactHostCommands function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. • https://github.com/zgimszhd61/CVE-2024-23118 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-23119 – Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-23119
09 Feb 2024 — Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the insertGraphTemplate function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. • https://www.zerodayinitiative.com/advisories/ZDI-24-113 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-0637 – Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-0637
09 Feb 2024 — Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateDirectory function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. • https://www.zerodayinitiative.com/advisories/ZDI-24-118 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •