centreon CVE Vulnerabilities & Metrics

Focus on centreon vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About centreon Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with centreon. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total centreon CVEs: 75
Earliest CVE date: 20 Dec 2007, 20:46 UTC
Latest CVE date: 21 Aug 2024, 17:15 UTC

Latest CVE reference: CVE-2024-5725

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -50.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -50.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical centreon CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.77

Max CVSS: 10.0

Critical CVEs (≥9): 8

CVSS Range vs. Count

Range Count
0.0-3.9 23
4.0-6.9 37
7.0-8.9 11
9.0-10.0 8

CVSS Distribution Chart

Top 5 Highest CVSS centreon CVEs

These are the five CVEs with the highest CVSS scores for centreon, sorted by severity first and recency.

All CVEs for centreon

CVE-2024-5725 centreon vulnerability CVSS: 0 21 Aug 2024, 17:15 UTC

Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the initCurveList function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the apache user. Was ZDI-CAN-22683.

CVE-2024-5723 centreon vulnerability CVSS: 0 21 Aug 2024, 17:15 UTC

Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateServiceHost function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the apache user. Was ZDI-CAN-23294.

CVE-2023-51633 centreon vulnerability CVSS: 0 03 May 2024, 03:16 UTC

Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability. The specific flaw exists within the processing of the sysName OID in SNMP. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-20731.

CVE-2022-42429 centreon vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18557.

CVE-2022-42428 centreon vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18410.

CVE-2022-42427 centreon vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18541.

CVE-2022-42426 centreon vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18554.

CVE-2022-42425 centreon vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18555.

CVE-2022-42424 centreon vulnerability CVSS: 0 29 Mar 2023, 19:15 UTC

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18556.

CVE-2022-41142 centreon vulnerability CVSS: 0 26 Jan 2023, 18:59 UTC

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18304.

CVE-2022-3827 centreon vulnerability CVSS: 0 02 Nov 2022, 13:15 UTC

A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated remotely. The name of the patch is 293b10628f7d9f83c6c82c78cf637cbe9b907369. It is recommended to apply a patch to fix this issue. VDB-212794 is the identifier assigned to this vulnerability.

CVE-2022-39988 centreon vulnerability CVSS: 0 06 Oct 2022, 18:16 UTC

A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML via a crafted payload injected into the Service>Templates service_alias parameter.

CVE-2022-40044 centreon vulnerability CVSS: 0 26 Sep 2022, 16:15 UTC

Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

CVE-2022-40043 centreon vulnerability CVSS: 0 26 Sep 2022, 16:15 UTC

Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.

CVE-2022-36194 centreon vulnerability CVSS: 0 29 Aug 2022, 06:15 UTC

Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.

CVE-2022-34872 centreon vulnerability CVSS: 0 03 Aug 2022, 16:15 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of Virtual Metrics. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16336.

CVE-2022-34871 centreon vulnerability CVSS: 0 03 Aug 2022, 16:15 UTC

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335.

CVE-2020-22345 centreon vulnerability CVSS: 9.0 18 Aug 2021, 21:15 UTC

/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.

CVE-2021-37558 centreon vulnerability CVSS: 7.5 03 Aug 2021, 16:15 UTC

A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a valid Knowledge Base URL is configured on the Knowledge Base configuration page and points to a MediaWiki instance. This relates to the proxy feature in class/centreon-knowledge/ProceduresProxy.class.php and include/configuration/configKnowledge/proxy/proxy.php.

CVE-2021-37557 centreon vulnerability CVSS: 6.5 03 Aug 2021, 16:15 UTC

A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.

CVE-2021-37556 centreon vulnerability CVSS: 6.5 03 Aug 2021, 16:15 UTC

A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end parameters.

CVE-2021-28053 centreon vulnerability CVSS: 6.5 16 Jul 2021, 16:15 UTC

An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A SQL injection vulnerability in "Configuration > Users > Contacts / Users" allows remote authenticated users to execute arbitrary SQL commands via the Additional Information parameters.

CVE-2021-28054 centreon vulnerability CVSS: 3.5 16 Jul 2021, 15:15 UTC

An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. A Stored Cross-Site Scripting (XSS) issue in "Configuration > Hosts" allows remote authenticated users to inject arbitrary web script or HTML via the Alias parameter.

CVE-2021-27676 centreon vulnerability CVSS: 3.5 26 May 2021, 11:15 UTC

Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page.

CVE-2021-26804 centreon vulnerability CVSS: 4.0 04 May 2021, 17:15 UTC

Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.

CVE-2021-28055 centreon vulnerability CVSS: 4.3 15 Apr 2021, 19:15 UTC

An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.

CVE-2020-22425 centreon vulnerability CVSS: 6.5 15 Feb 2021, 18:15 UTC

Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.

CVE-2020-13628 centreon vulnerability CVSS: 4.3 27 May 2020, 16:15 UTC

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

CVE-2020-13627 centreon vulnerability CVSS: 4.3 27 May 2020, 16:15 UTC

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

CVE-2020-10946 centreon vulnerability CVSS: 4.3 27 May 2020, 16:15 UTC

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

CVE-2020-10945 centreon vulnerability CVSS: 3.3 27 May 2020, 16:15 UTC

Centreon before 19.10.7 exposes Session IDs in server responses.

CVE-2020-13252 centreon vulnerability CVSS: 9.0 21 May 2020, 04:15 UTC

Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.

CVE-2019-19699 centreon vulnerability CVSS: 9.0 06 Apr 2020, 16:15 UTC

There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a custom main.php?p=60803&type=3 command. The user must then set the Pollers Post-Restart Command to this previously created command via the main.php?p=60901&o=c&server_id=1 URI. This is triggered via an export of the Poller Configuration.

CVE-2019-19487 centreon vulnerability CVSS: 6.5 20 Mar 2020, 03:15 UTC

Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.

CVE-2019-19486 centreon vulnerability CVSS: 4.0 20 Mar 2020, 03:15 UTC

Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.

CVE-2019-19484 centreon vulnerability CVSS: 5.8 20 Mar 2020, 03:15 UTC

Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.

CVE-2019-17647 centreon vulnerability CVSS: 7.5 05 Mar 2020, 20:15 UTC

An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.

CVE-2019-17646 centreon vulnerability CVSS: 5.0 05 Mar 2020, 20:15 UTC

An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.

CVE-2019-17645 centreon vulnerability CVSS: 5.0 05 Mar 2020, 17:15 UTC

An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/service/refreshMacroAjax.php.

CVE-2019-17642 centreon vulnerability CVSS: 6.8 05 Mar 2020, 17:15 UTC

An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.

CVE-2019-17644 centreon vulnerability CVSS: 5.0 04 Mar 2020, 22:15 UTC

An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/host/refreshMacroAjax.php.

CVE-2019-17643 centreon vulnerability CVSS: 5.0 04 Mar 2020, 22:15 UTC

An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. It provides sensitive information via an unauthenticated direct request for include/monitoring/recurrentDowntime/GetXMLHost4Services.php.

CVE-2020-9463 centreon vulnerability CVSS: 9.0 28 Feb 2020, 18:15 UTC

Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.

CVE-2019-15299 centreon vulnerability CVSS: 6.5 24 Feb 2020, 13:15 UTC

An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.

CVE-2019-20327 centreon vulnerability CVSS: 7.2 16 Jan 2020, 15:15 UTC

Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrapper_perl is a setuid executable allowing execution of Perl scripts with root privileges.)

CVE-2019-15300 centreon vulnerability CVSS: 6.5 27 Nov 2019, 14:15 UTC

A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.

CVE-2019-15298 centreon vulnerability CVSS: 6.5 27 Nov 2019, 14:15 UTC

A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.

CVE-2019-16195 centreon vulnerability CVSS: 4.3 26 Nov 2019, 18:15 UTC

Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.

CVE-2019-16406 centreon vulnerability CVSS: 7.2 21 Nov 2019, 18:15 UTC

Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attackers to gain privileges via a Trojan horse Centreon-autodisco executable file that is launched by cron.

CVE-2019-16405 centreon vulnerability CVSS: 9.0 21 Nov 2019, 18:15 UTC

Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.

CVE-2019-17501 centreon vulnerability CVSS: 9.0 14 Oct 2019, 02:15 UTC

Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Commands > Discovery screen). CVE-2019-17501 and CVE-2019-16405 are similar to one another and may be the same.

CVE-2019-17105 centreon vulnerability CVSS: 5.0 08 Oct 2019, 15:15 UTC

The token generator in index.php in Centreon Web before 2.8.27 is predictable.

CVE-2018-21024 centreon vulnerability CVSS: 7.5 08 Oct 2019, 15:15 UTC

licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

CVE-2019-17108 centreon vulnerability CVSS: 4.3 08 Oct 2019, 13:15 UTC

Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.

CVE-2019-17107 centreon vulnerability CVSS: 6.5 08 Oct 2019, 13:15 UTC

minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this, but that is incorrect.

CVE-2019-17106 centreon vulnerability CVSS: 4.0 08 Oct 2019, 13:15 UTC

In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.

CVE-2019-17104 centreon vulnerability CVSS: 5.0 08 Oct 2019, 13:15 UTC

In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.

CVE-2018-21025 centreon vulnerability CVSS: 10.0 08 Oct 2019, 13:15 UTC

In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configuration files.

CVE-2018-21023 centreon vulnerability CVSS: 6.5 08 Oct 2019, 13:15 UTC

getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.

CVE-2018-21022 centreon vulnerability CVSS: 6.5 08 Oct 2019, 13:15 UTC

makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.

CVE-2018-21021 centreon vulnerability CVSS: 6.5 08 Oct 2019, 13:15 UTC

img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.

CVE-2018-21020 centreon vulnerability CVSS: 5.0 08 Oct 2019, 13:15 UTC

In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.

CVE-2019-16194 centreon vulnerability CVSS: 7.5 25 Sep 2019, 16:15 UTC

SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.

CVE-2019-13024 centreon vulnerability CVSS: 9.0 01 Jul 2019, 19:15 UTC

Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).

CVE-2018-19312 centreon vulnerability CVSS: 6.5 16 Nov 2018, 19:29 UTC

Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.

CVE-2018-19311 centreon vulnerability CVSS: 3.5 16 Nov 2018, 19:29 UTC

Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.

CVE-2018-19281 centreon vulnerability CVSS: 7.5 14 Nov 2018, 20:29 UTC

Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.

CVE-2018-19280 centreon vulnerability CVSS: 4.3 14 Nov 2018, 20:29 UTC

Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.

CVE-2018-19271 centreon vulnerability CVSS: 6.5 14 Nov 2018, 11:29 UTC

Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.

CVE-2018-11589 centreon vulnerability CVSS: 7.5 25 Jun 2018, 18:29 UTC

Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.

CVE-2018-11588 centreon vulnerability CVSS: 3.5 25 Jun 2018, 18:29 UTC

Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArguments.php.

CVE-2018-11587 centreon vulnerability CVSS: 7.5 25 Jun 2018, 18:29 UTC

There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.

CVE-2015-7672 centreon vulnerability CVSS: 3.5 07 Sep 2017, 20:29 UTC

Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).

CVE-2015-1561 centreon vulnerability CVSS: 6.5 14 Jul 2015, 16:59 UTC

The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.

CVE-2015-1560 centreon vulnerability CVSS: 7.5 14 Jul 2015, 16:59 UTC

SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to include/common/XmlTree/GetXmlTree.php.

CVE-2008-1178 centreon vulnerability CVSS: 4.3 06 Mar 2008, 00:44 UTC

Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119.

CVE-2008-1179 centreon vulnerability CVSS: 4.3 06 Mar 2008, 00:44 UTC

Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) title parameters. NOTE: some of these details are obtained from third party information.

CVE-2008-1119 centreon vulnerability CVSS: 5.0 03 Mar 2008, 22:44 UTC

Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter.

CVE-2007-6485 centreon vulnerability CVSS: 7.5 20 Dec 2007, 20:46 UTC

Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.