PoC Index

CVE-2015-1560

HIGH 7.5EPSS 6.7%

SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to include/common/XmlTree/GetXmlTree.php.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
6.69% chance of exploitation in the next 30 days, 93th percentile
Published
2015-07-14
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related