The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2015-07-14T16:00:00

Updated: 2019-07-30T19:09:44

Reserved: 2015-02-08T00:00:00


Link: CVE-2015-1561

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-07-14T16:59:01.267

Modified: 2019-07-30T20:15:12.037


Link: CVE-2015-1561

JSON object: View

cve-icon Redhat Information

No data.

CWE