CVE-2014-3829: Code Injection
Published Oct 23, 2014
·Updated
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sessionid or (2) templateid parameter, related to the commandline variable.
Affected Software
2 affected components
Merethis Centreon=2.5.1
Merethis Centreon Enterprise Server=2.2
Event History
Oct 23, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3829?
CVE-2014-3829 is classified as a critical vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2014-3829?
To address CVE-2014-3829, upgrade to Centreon version 2.5.3 or later.
3
What systems are affected by CVE-2014-3829?
CVE-2014-3829 affects Centreon 2.5.1 and Centreon Enterprise Server 2.2.
4
Can CVE-2014-3829 be exploited remotely?
Yes, CVE-2014-3829 can be exploited remotely using shell metacharacters.
5
What components are involved in the exploitation of CVE-2014-3829?
The exploitation of CVE-2014-3829 involves the session_id or template_id parameters in displayServiceStatus.php.