← Back

CVE-2014-3829

nvd nist
Published: Oct 23, 2014Modified: May 6, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.

Affected (2)

2 products
Centreon
Centreon Enterprise Server
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.5.1
Version 2.2

Timeline

No history available yet.