PT-2011-4949 · Merethis · Centreon
Christophe De La Fuente
·
Publicado
2011-11-10
·
Atualizado
2012-02-14
·
CVE-2011-4431
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Merethis Centreon versions prior to 2.3.2
Description
The issue allows remote authenticated users to execute arbitrary commands. This is achieved by exploiting a directory traversal vulnerability in the
main.php file. The vulnerability can be triggered by including a .. (dot dot) in the command name parameter.Recommendations
For versions prior to 2.3.2, update to version 2.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the
main.php file or limiting the use of the command name parameter to prevent exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centreon