CVE-2007-6485: Code Injection
Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6485?
CVE-2007-6485 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2007-6485?
To fix CVE-2007-6485, it's recommended to update Centreon to a version that addresses this vulnerability.
Who is affected by CVE-2007-6485?
CVE-2007-6485 affects users of Centreon version 1.4.1.
What types of attacks can be executed through CVE-2007-6485?
CVE-2007-6485 allows remote attackers to execute arbitrary PHP code on the affected server.
Is there a workaround for CVE-2007-6485 if I cannot update?
A temporary workaround for CVE-2007-6485 is to restrict access to the affected PHP files, but this is not as secure as applying a patch.