CVE-2012-5967: SQL Injection
Published Dec 19, 2012
·Updated
SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execute arbitrary SQL commands via the menu parameter.
Affected Software
8 affected components
Merethis Centreon=2.3.3
Merethis Centreon=2.3.4
Merethis Centreon=2.3.5
Merethis Centreon=2.3.6
Merethis Centreon=2.3.7
Merethis Centreon=2.3.8
Merethis Centreon=2.3.9
Merethis Centreon=2.3.9-4
Event History
Dec 19, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5967?
CVE-2012-5967 has a medium severity rating due to its potential for remote SQL command execution by authenticated users.
2
How do I fix CVE-2012-5967?
To fix CVE-2012-5967, upgrade to Centreon version 2.6.0 or later.
3
Which versions of Centreon are affected by CVE-2012-5967?
CVE-2012-5967 affects Centreon versions 2.3.3 through 2.3.9-4.
4
What type of vulnerability is CVE-2012-5967?
CVE-2012-5967 is an SQL injection vulnerability.
5
Who can exploit CVE-2012-5967?
CVE-2012-5967 can be exploited by remote authenticated users.