CVE-2014-3829

Centreon 2.5.1 and Centreon Enterprise Server 2.2 - Remote Code Execution via session_id or template_id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-3829. PoCs published by Metasploit, MaZ, juan vazquez, including Metasploit module exploits/linux/http/centreon_sqli_exec.

AI-analyzed exploit summary This Metasploit module exploits SQL and command injection vulnerabilities in Centreon (CVE-2014-3829) to achieve remote code execution. It leverages a valid session ID to inject malicious payloads via the displayServiceStatus.php component.

Description

displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappslinux
https://www.exploit-db.com/exploits/41676

This Metasploit module exploits SQL and command injection vulnerabilities in Centreon (CVE-2014-3829) to achieve remote code execution. It leverages a valid session ID to inject malicious payloads via the displayServiceStatus.php component.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon 2.5.1 and prior, Centreon Enterprise Server 2.2 and prior
No auth needed
Prerequisites: Valid session in centreon.session table
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by MaZ, juan vazquez · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/centreon_sqli_exec.rb

This Metasploit module exploits a combination of SQL injection and command injection in Centreon's displayServiceStatus.php component, allowing arbitrary command execution without authentication, provided a valid session exists in the centreon.session table.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon 2.5.1 and prior, Centreon Enterprise Server 2.2 and prior
No auth needed
Prerequisites: A valid session in the centreon.session table (e.g., from a prior login)
devstral-2 · analyzed Apr 22, 2026 Full analysis →

References (4)

Core 4

Scores

EPSS 0.8620
EPSS Percentile 99.4%

Details

CWE
CWE-94
Status published
Products (2)
merethis/centreon 2.5.1
merethis/centreon_enterprise_server 2.2
Published Oct 23, 2014
Tracked Since Feb 18, 2026