Centreon 2.6.1 Command Injection
Posted by deepcore on September 30, 2015 – 7:55 am
Centreon version 2.6.1 suffers from a command injection vulnerability. The POST parameter ‘persistant’ which serves for making a new service run in the background is not properly sanitized before being used to execute commands. This can be exploited to inject and execute arbitrary shell commands as well as using cross site request forgery attacks.
Post a reply
You must be logged in to post a comment.