CVE-2020-13252: OS Command Injection
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabasestatuspath (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-13252.
What is the severity of CVE-2020-13252?
The severity of CVE-2020-13252 is critical with a score of 8.8.
What is the affected software?
The affected software is Centreon version 19.04.0 to 19.04.15.
How does CVE-2020-13252 allow remote attackers to execute arbitrary OS commands?
CVE-2020-13252 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in the RRDdatabase_status_path parameter of a main.get.php request and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.
Are there any references for further information on CVE-2020-13252?
Yes, you can find further information on CVE-2020-13252 at the following references: [1] [2] [3].