CVE

Id
78838  
CVE No.
CVE-2015-1561  
Status
Candidate  
Description
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.  
Phase
Assigned (20150208)  
Votes
None (candidate not yet proposed)  
Comments