Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-3828
Description:Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.php, (2) the sid parameter to views/graphs/GetXmlTree.php, (3) the session_id parameter to views/graphs/graphStatus/displayServiceStatus.php, (4) the mnftr_id parameter to configuration/configObject/traps/GetXMLTrapsForVendor.php, or (5) the index parameter to common/javascript/commandGetArgs/cmdGetExample.php in include/.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-3828
BugTraq ID: 70648
http://www.securityfocus.com/bid/70648
CERT/CC vulnerability note: VU#298796
http://www.kb.cert.org/vuls/id/298796
http://seclists.org/fulldisclosure/2014/Oct/78




© 1998-2025 E-Soft Inc. All rights reserved.