CVE-2015-1561
Summary
| CVE | CVE-2015-1561 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-14 16:59:01 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| enh(secu): removing unused file · centreon/centreon@a78c60a · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | forge.centreon.com | |
| Merethis Centreon 2.5.4 SQL Injection / Remote Command Execution ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 994844 PHP (Composer) Security Update for centreon/centreon (GHSA-c4fj-3wqq-g9c9)