Release date: 2011-11-04
Updated on: 2011-11-21
Affected Systems:
Centreon 2.3.1
Unaffected system:
Centreon 2.3.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50568
Cve id: CVE-2011-4431
Centreon is an open-source software used to work with nagios. It manages nagios through pages and monitors networks, operating systems, and applications through third-party components.
The input verification vulnerability exists in Centreon's "command_name" parameter implementation. Attackers can exploit this vulnerability to execute arbitrary commands in the command. All accounts that can access "Configuration> Nagios> Checks" can execute commands.
<* Source: Christophe De La Fuente
Link: https://www.trustwave.com/spiderlabs/advisories/TWSL2011-017.txt
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
'Cat/etc/passwd ':
Http://example.domain/centreon/main.php? P = 60706 & command_name =/Centreon/SNMP /.. /.. /.. /.. /bin/cat % 20/etc/passwd % 20% 23 & o = h & min = 1
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Centreon
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.centreon.com/