CVE-2019-13024

CVE-2019-13024

Centreon V19.04 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).

Source: CVE-2019-13024

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다