First published: Thu Dec 20 2007(Updated: )
Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon Web | =1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6485 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2007-6485, it's recommended to update Centreon to a version that addresses this vulnerability.
CVE-2007-6485 affects users of Centreon version 1.4.1.
CVE-2007-6485 allows remote attackers to execute arbitrary PHP code on the affected server.
A temporary workaround for CVE-2007-6485 is to restrict access to the affected PHP files, but this is not as secure as applying a patch.