Vulnerabilities (CVE)

Filtered by vendor Centreon Subscribe
Filtered by product Centreon Web
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11587 1 Centreon 2 Centreon, Centreon Web 2018-08-30 7.5 HIGH 9.8 CRITICAL
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.
CVE-2018-11589 1 Centreon 2 Centreon, Centreon Web 2018-08-28 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php.