Back to Database
Status published
Medium
CVE-2011-4431
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2...
Vulnerability Description
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-4431
Credits & Attribution
No credits recorded in the NVD database.
References
More from merethis
View All →CVE-2014-3829
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed...
Critical
10
CVE-2014-3828
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise...
Critical
10
CVE-2011-4432
www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a...
Medium
5
CVE-2010-1301
SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote...
High
7.5
CVE-2009-4368
Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact...
Critical
10
Affected Vendor
merethis
View all reports →Affected Software
centreon
Vulnerable Versions:
0, 1.4, 1.4.1, 1.4.2, 1.4.2.1, 1.4.2.2, 1.4.2.3, 1.4.2.4, 1.4.2.5, 1.4.2.6, 1.4.2.7, 2.0, 2.0.1, 2.0.2, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.1.9, 2.1.10, 2.1.11, 2.1.12, 2.1.13, 2.2, 2.2.1, 2.2.2, 2.3.0
Timeline
Official Publish:
November 10th, 2011
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.