Centreon and Centreon Enterprise Server CVE-2014-3828 Multiple SQL Injection Vulnerabilities
BID:70648
Info
Centreon and Centreon Enterprise Server CVE-2014-3828 Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 70648 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3828 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2014 12:00AM |
| Updated: | Oct 31 2014 12:59AM |
| Credit: | yoloswag |
| Vulnerable: |
Centreon Centreon 2.3.2 Centreon Centreon 2.3.1 Centreon Centreon 2.1.5 Centreon Centreon 2.1.4 Centreon Centreon 2.1.3 Centreon Centreon 2.1.2 Centreon Centreon 2.1.1 Centreon Centreon 2.0.2 Centreon Centreon 2.0.1 Centreon Centreon 1.4.2 .4 Centreon Centreon 1.4.1 Centreon Centreon 2.0.RC5 Centreon Centreon 2.0.RC4 Centreon Centreon 2.0.RC3 Centreon Centreon 2.0.RC2 Centreon Centreon 2.0.RC1 Centreon Centreon 2.0 Centreon Centreon 1.4.2.3 Centreon Centreon 1.4.2.2 Centreon Centreon 1.4 |
| Not Vulnerable: | |
Discussion
Centreon and Centreon Enterprise Server CVE-2014-3828 Multiple SQL Injection Vulnerabilities
Centreon and Centreon Enterprise Server are prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are vulnerable:
Centreon 2.5.1 and prior versions
Centreon Enterprise Server 2.2 and prior versions
Centreon and Centreon Enterprise Server are prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are vulnerable:
Centreon 2.5.1 and prior versions
Centreon Enterprise Server 2.2 and prior versions
Exploit / POC
Centreon and Centreon Enterprise Server CVE-2014-3828 Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following metasploit module is available:
Attackers can use a browser to exploit these issues.
The following metasploit module is available:
Solution / Fix
Centreon and Centreon Enterprise Server CVE-2014-3828 Multiple SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Centreon and Centreon Enterprise Server CVE-2014-3828 Multiple SQL Injection Vulnerabilities
References:
References:
- centreon Homepage (centreon)