
We found results for “”
CVE-2018-11589
Good to know:

Date: June 25, 2018
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.
Language: PHP
Severity Score
Related Resources (9)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89Top Fix

Upgrade Version
Upgrade to version centreon/centreon - dev-MON-5609-sonardev-20-04;centreon/centreon - dev-SECU-34;centreon/centreon - dev-MON-7098-secure-graph-split;centreon/centreon - dev-MON-6617-meitrcs-acl;centreon/centreon - dev-poc-loadbalancer;centreon/centreon - dev-MON-12220-Replace-Header-scss-module-with-material-makeStyles(pollerMenu);centreon/centreon - dev-MON-4379-add-missing-centreonIndexes.json-master;centreon/centreon - dev-MON-6000-regexp-comparison;centreon/centreon - dev-upgrade-to-2.8.36;centreon/centreon - dev-command-poc;centreon/centreon - dev-hide-macro-password;centreon/centreon - dev-upgrade-to-2.8.38;centreon/centreon - dev-change_home_centreon;centreon/centreon - dev-MON-3345-popin-pp-manager;centreon/centreon - dev-MON-7099-secure-engine-form;centreon/centreon - dev-new_features_debian;centreon/centreon - dev-poc-swc;centreon/centreon - dev-MON-fix-2-8-job;centreon/centreon - dev-MON-7196-Translation-for-Downtime-in-Timeline;centreon/centreon - dev-MON-6788;centreon/centreon - dev-dependabot/npm_and_yarn/query-string-7.1.1;centreon/centreon - dev-MON-3201;centreon/centreon - dev-improve_snmpd_config;centreon/centreon - 2.8.20;centreon/centreon - dev-MON-5531-technical-information-leak;centreon/centreon - dev-react-relative-path;centreon/centreon - dev-translations-test;centreon/centreon - dev-MON-6772-openssl;centreon/centreon - dev-MON-6204-check-command;centreon/centreon - dev-MON-5549-display-service-graphs;centreon/centreon - dev-prepare-2.8.38-rn;centreon/centreon - dev-realign-front-master
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |