CVE-2019-13024
Summary
| CVE | CVE-2019-13024 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-01 19:15:00 UTC |
| Updated | 2019-07-26 14:15:00 UTC |
| Description | Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands). |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Centreon v19.04 Remote Code Execution (CVE-2019-13024) - Shells.Systems | MISC | shells.systems | Exploit, Third Party Advisory |
| Centreon v19.04 Authenticated Remote Code Execution · GitHub | MISC | gist.github.com | Exploit, Third Party Advisory |
| Centreon 19.04 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Centreon Web 19.04.3 — Centreon 19.04.0 documentation | CONFIRM | documentation.centreon.com | |
| add escapeshellarg to nagios_bin binary passed to shell_exec by sc979 · Pull Request #7694 · centreon/centreon · GitHub | CONFIRM | github.com | |
| Centreon Web 18.10.6 — Centreon 19.04.0 documentation | CONFIRM | documentation.centreon.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.