CVE-2014-3828: SQL Injection
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the indexid parameter to views/graphs/common/makeXMLListMetrics.php, (2) the sid parameter to views/graphs/GetXmlTree.php, (3) the sessionid parameter to views/graphs/graphStatus/displayServiceStatus.php, (4) the mnftrid parameter to configuration/configObject/traps/GetXMLTrapsForVendor.php, or (5) the index parameter to common/javascript/commandGetArgs/cmdGetExample.php in include/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3828?
CVE-2014-3828 is classified as a critical vulnerability due to its potential for remote SQL command execution.
How do I fix CVE-2014-3828?
To remediate CVE-2014-3828, upgrade to Centreon version 2.5.3 or later.
What software is affected by CVE-2014-3828?
CVE-2014-3828 affects Centreon version 2.5.1 and Centreon Enterprise Server version 2.2.
Can CVE-2014-3828 be exploited remotely?
Yes, CVE-2014-3828 can be exploited by remote attackers to execute arbitrary SQL commands.
What are the consequences of exploiting CVE-2014-3828?
Exploitation of CVE-2014-3828 can lead to unauthorized data access and manipulation within the vulnerable database.