CVE-2018-11589
Summary
| CVE | CVE-2018-11589 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-25 18:29:00 UTC |
| Updated | 2018-08-28 17:14:00 UTC |
| Description | Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Centreon | Centreon | 3.4.6 | All | All | All |
| Application | Centreon | Centreon | 3.4.6 | All | All | All |
| Application | Centreon | Centreon Web | 2.8.23 | All | All | All |
| Application | Centreon | Centreon Web | 2.8.23 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix(sec): Fix SQL Injection in Virtual Metrics by leoncx · Pull Request #6257 · centreon/centreon · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| fix(sec): Fix SQL injection in dashboard by leoncx · Pull Request #6250 · centreon/centreon · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Releases · centreon/centreon · GitHub | CONFIRM | github.com | Third Party Advisory |
| fix(sec): Fix SQL injection in Curve template by leoncx · Pull Request #6256 · centreon/centreon · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| fix(sec): Fix SQL Injection in administration logs by leoncx · Pull Request #6255 · centreon/centreon · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| fix(sec): Fix SQL injection on graphs by leoncx · Pull Request #6251 · centreon/centreon · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Centreon Web 2.8.24 — Centreon 19.04.0 documentation | CONFIRM | documentation.centreon.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.