CVE-2011-4431

EUVD-2011-4360
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
merethiscentreon
𝑥
≤ 2.3.1
merethiscentreon
1.4
merethiscentreon
1.4.1
merethiscentreon
1.4.2
merethiscentreon
1.4.2.1
merethiscentreon
1.4.2.2
merethiscentreon
1.4.2.3
merethiscentreon
1.4.2.4
merethiscentreon
1.4.2.5
merethiscentreon
1.4.2.6
merethiscentreon
1.4.2.7
merethiscentreon
2.0:b2
merethiscentreon
2.0:b3
merethiscentreon
2.0:b4
merethiscentreon
2.0:b5
merethiscentreon
2.0:b6
merethiscentreon
2.0:rc1
merethiscentreon
2.0:rc2
merethiscentreon
2.0:rc3
merethiscentreon
2.0:rc4
merethiscentreon
2.0:rc5
merethiscentreon
2.0.1
merethiscentreon
2.0.2
merethiscentreon
2.1.0
merethiscentreon
2.1.1
merethiscentreon
2.1.2
merethiscentreon
2.1.3
merethiscentreon
2.1.4
merethiscentreon
2.1.5
merethiscentreon
2.1.6
merethiscentreon
2.1.7
merethiscentreon
2.1.8
merethiscentreon
2.1.9
merethiscentreon
2.1.10
merethiscentreon
2.1.11
merethiscentreon
2.1.12
merethiscentreon
2.1.13
merethiscentreon
2.2
merethiscentreon
2.2:b1
merethiscentreon
2.2:rc1
merethiscentreon
2.2:rc2
merethiscentreon
2.2.1
merethiscentreon
2.2.2
merethiscentreon
2.3.0
merethiscentreon
2.3.0:rc3
𝑥
= Vulnerable software versions