Lucene search

K
prionPRIOn knowledge basePRION:CVE-2015-1561
HistoryJul 14, 2015 - 4:59 p.m.

Code injection

2015-07-1416:59:00
PRIOn knowledge base
www.prio-n.com
7

AI Score

7.6

Confidence

Low

EPSS

0.008

Percentile

81.3%

The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.

AI Score

7.6

Confidence

Low

EPSS

0.008

Percentile

81.3%