Diverse vulnerabilità SQL injection in Centreon 3.4.6 tra cui Centreon Web 2.8.23 permettono attacchi tramite il parametro searchU nel viewLogs.php, il parametro id nel GetXmlHost.php, il parametro chartId nel ExportCSVServiceData.php, il parametro searchCurve in listComponentTemplates.php, o il parametro HOST_ID in makeXML_ListMetrics.php. |
https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html https://github.com/centreon/centreon/pull/6250 https://github.com/centreon/centreon/pull/6251 https://github.com/centreon/centreon/pull/6255 https://github.com/centreon/centreon/pull/6256 https://github.com/centreon/centreon/pull/6257 https://github.com/centreon/centreon/releases https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11589 |
Vulnerabilità: CVE-2018-11589
