VendorsMerethiscentreon1.4.2.5
Vulnerabilities

Merethis Centreon 1.4.2.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2009-4368
Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute tool, and (3) ldap import, possibly related to improper authentication.
Published 2009-12-21 · Modified
10.0EPSS 0.025
CVE-2011-4431
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter.
Published 2011-11-10 · Modified
6.51 PoCEPSS 0.062
CVE-2011-4432
www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.
Published 2011-11-10 · Modified
5.0EPSS 0.013