7.5
CVSSv2

CVE-2007-6485

Published: 20/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote malicious users to execute arbitrary PHP code via a URL in the fileOreonConf parameter to (1) MakeXML.php or (2) MakeXML4statusCounter.php in include/monitoring/engine/.

Vulnerable Product Search on Vulmon Subscribe to Product

centreon centreon 1.4.1

Exploits

By Michael Brooks Vulnerability Type: Multiple Remote File Inclusion Software: Oreon and Centreon Homepage:wwworeon-projectorg/ or wwwcentreoncom/ Versions: 14(Oreon) and 141(Centreon) The vulnerable file is: /oreon-14/www/include/monitoring/engine/MakeXMLphp Another,virtually identical RFI: /oreon-14/www/include/monito ...