« Volver al listado

CVE-2012-5967

Estado: ModificadaMedia (6.5)—

SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execute arbitrary SQL commands via the menu parameter.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-5967",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "Centreon",
          "product": "Centreon",
          "versions": [
            {
              "status": "affected",
              "version": "2.3.3 through 2.3.9-4"
            }
          ]
        },
        {
          "vendor": "Centreon",
          "product": "Centreon web",
          "versions": [
            {
              "status": "affected",
              "version": "fixed in 2.6.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-12-19T11:55:56.797",
  "references": [
    {
      "url": "http://forge.centreon.com/projects/centreon/repository/revisions/13749",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/856892",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://github.com/centreon/centreon/commit/434e291eebcd8f56771ac96b37831634fa52b6a8#diff-606758231371c4a66ae2668f7ad2b617",
      "source": "cret@cert.org"
    },
    {
      "url": "http://forge.centreon.com/projects/centreon/repository/revisions/13749",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/856892",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/centreon/centreon/commit/434e291eebcd8f56771ac96b37831634fa52b6a8#diff-606758231371c4a66ae2668f7ad2b617",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execute arbitrary SQL commands via the menu parameter."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de inyección SQL en el archivo menuXML.php en Centreon versiones 2.3.3 hasta 2.3.9-4 (corregido en Centreon web versión 2.6.0), permite a usuarios autenticados remotos ejecutar comandos SQL arbitrarios por medio del parámetro menu."
    }
  ],
  "lastModified": "2026-06-16T23:47:39.280",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:merethis:centreon:2.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC2A0E58-BBF4-4B90-8459-2F5729292267"
            },
            {
              "criteria": "cpe:2.3:a:merethis:centreon:2.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4846545B-525F-460F-9824-91E715FD5CF3"
            },
            {
              "criteria": "cpe:2.3:a:merethis:centreon:2.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "661A5C9D-35E9-42AD-A7B2-D772BA961C23"
            },
            {
              "criteria": "cpe:2.3:a:merethis:centreon:2.3.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C376F11-CF76-4E41-9C63-208B33554BC5"
            },
            {
              "criteria": "cpe:2.3:a:merethis:centreon:2.3.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDEBF54E-87B9-49A7-AB81-7587E194EB60"
            },
            {
              "criteria": "cpe:2.3:a:merethis:centreon:2.3.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "538EC7A7-42FE-40DA-9168-697BE1DD6E4F"
            },
            {
              "criteria": "cpe:2.3:a:merethis:centreon:2.3.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC431677-ED5B-49D2-A5AE-9DE118EFE39D"
            },
            {
              "criteria": "cpe:2.3:a:merethis:centreon:2.3.9-4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C67AF8F9-2389-4023-9D57-E211B5126B90"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}