Centreon Web Interface 2.5.3 Command Execution

Discussion in 'News Aggregator' started by Packet Storm, 28 Jul 2016.

  1. Packet Storm

    Packet Storm Guest

    Centreon Web Interface versions 2.5.3 and below utilize an ECHO for logging SQL errors. This functionality can be abused for arbitrary code execution, and can be triggered via the login screen prior to authentication.

    Continue reading...
     

Share This Page

Loading...