Show filters
92 Total Results
Displaying 41-50 of 92
Sort by:
Attacker Value
Unknown

CVE-2019-19487

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.
Attacker Value
Unknown

CVE-2019-19486

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.
Attacker Value
Unknown

CVE-2019-19484

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.
Attacker Value
Unknown

CVE-2019-17647

Disclosure Date: March 05, 2020 (last updated February 21, 2025)
An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.
Attacker Value
Unknown

CVE-2019-17646

Disclosure Date: March 05, 2020 (last updated February 21, 2025)
An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.
Attacker Value
Unknown

CVE-2019-17642

Disclosure Date: March 05, 2020 (last updated February 21, 2025)
An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.
Attacker Value
Unknown

CVE-2019-17645

Disclosure Date: March 05, 2020 (last updated February 21, 2025)
An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/service/refreshMacroAjax.php.
Attacker Value
Unknown

CVE-2019-17643

Disclosure Date: March 04, 2020 (last updated February 21, 2025)
An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. It provides sensitive information via an unauthenticated direct request for include/monitoring/recurrentDowntime/GetXMLHost4Services.php.
Attacker Value
Unknown

CVE-2019-17644

Disclosure Date: March 04, 2020 (last updated February 21, 2025)
An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/host/refreshMacroAjax.php.
Attacker Value
Unknown

CVE-2019-15299

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.