Записи merethis
7 опубликованных записей вендора merethis.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 28,6 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-310 Cryptographic Issues1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2014-3829Готовый эксплойт | displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execumerethis · centreon · CWE-94 | Критическая10,0 | — | 80,2 % | 22 окт. 2014 г. |
62На этой неделе | CVE-2014-3828Готовый эксплойт | Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attacmerethis · centreon · CWE-89 | Критическая10,0 | — | 72,7 % | 22 окт. 2014 г. |
41В плане | CVE-2009-4368Эксплойта нет | Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute tomerethis · centreon | Критическая10,0 | — | 2,5 % | 21 дек. 2009 г. |
31Наблюдать | CVE-2010-1301Proof of concept | SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parametemerethis · centreon · CWE-89 | Высокая7,5 | — | 2,6 % | 7 апр. 2010 г. |
28Наблюдать | CVE-2011-4431Proof of concept | Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commamerethis · centreon · CWE-22 | Средняя6,5 | — | 6,0 % | 9 нояб. 2011 г. |
27Наблюдать | CVE-2012-5967Proof of concept | SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated usersmerethis · centreon · CWE-89 | Средняя6,5 | — | 3,3 % | 19 дек. 2012 г. |
20Наблюдать | CVE-2011-4432Эксплойта нет | www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a pamerethis · centreon · CWE-310 | Средняя5,0 | — | 1,3 % | 9 нояб. 2011 г. |
- CVE-2014-382964На этой неделе
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execu
КритическаяCVSS 10,0Готовый эксплойтEPSS 80 %merethis · centreon22 окт. 2014 г.
- CVE-2014-382862На этой неделе
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attac
КритическаяCVSS 10,0Готовый эксплойтEPSS 73 %merethis · centreon22 окт. 2014 г.
- CVE-2009-436841В плане
Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute to
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %merethis · centreon21 дек. 2009 г.
- CVE-2010-130131Наблюдать
SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id paramete
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %merethis · centreon7 апр. 2010 г.
- CVE-2011-443128Наблюдать
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary comma
СредняяCVSS 6,5Proof of conceptEPSS 6 %merethis · centreon9 нояб. 2011 г.
- CVE-2012-596727Наблюдать
SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users
СредняяCVSS 6,5Proof of conceptEPSS 3 %merethis · centreon19 дек. 2012 г.
- CVE-2011-443220Наблюдать
www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a pa
СредняяCVSS 5,0Эксплойта нетEPSS 1 %merethis · centreon9 нояб. 2011 г.