CVE-2019-15298
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.
Se encontró un problema en Centreon Web versiones hasta 19.04.3. Una inyección de comando autenticada está presente en la página include/configuration/configObject/traps-mibs/formMibs.php. Esta página es llamada desde la interfaz de administración de Centreon. Esta es la funcionalidad de administración mibs que contiene un formulario de archivo. Al momento del envío de un archivo, el parámetro mnftr es enviado a la página y no es filtrado apropiadamente. Esto permite inyectar comandos de Linux directamente.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-08-21 CVE Reserved
- 2019-11-27 CVE Published
- 2024-08-05 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.html | Release Notes | |
https://github.com/centreon/centreon/pull/8023 | Third Party Advisory | |
https://www.certilience.fr/2019/08/CVE-2019-15298-vulnerabilit%C3%A9-centreon-command-injection | Not Applicable |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Centreon Search vendor "Centreon" | Centreon Web Search vendor "Centreon" for product "Centreon Web" | >= 2.8.1 < 2.8.30 Search vendor "Centreon" for product "Centreon Web" and version " >= 2.8.1 < 2.8.30" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Web Search vendor "Centreon" for product "Centreon Web" | >= 18.10.0 < 18.10.8 Search vendor "Centreon" for product "Centreon Web" and version " >= 18.10.0 < 18.10.8" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Web Search vendor "Centreon" for product "Centreon Web" | >= 19.04.0 < 19.04.5 Search vendor "Centreon" for product "Centreon Web" and version " >= 19.04.0 < 19.04.5" | - |
Affected
| ||||||
Centreon Search vendor "Centreon" | Centreon Web Search vendor "Centreon" for product "Centreon Web" | >= 19.10.0 < 19.10.2 Search vendor "Centreon" for product "Centreon Web" and version " >= 19.10.0 < 19.10.2" | - |
Affected
|