CVE-2015-1560

Centreon < 2.5.4 - SQL Injection via sid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-1560. PoCs published by Iansus.

AI-analyzed exploit summary This repository contains a Python-based exploit for CVE-2015-1560 and CVE-2015-1561, targeting Centreon <= 2.5.4. It includes blind SQL injection and command execution capabilities via session manipulation.

Description

SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to include/common/XmlTree/GetXmlTree.php.

Exploits (2)

nomisec WORKING POC 3 stars
by Iansus · poc
https://github.com/Iansus/Centreon-CVE-2015-1560_1561

This repository contains a Python-based exploit for CVE-2015-1560 and CVE-2015-1561, targeting Centreon <= 2.5.4. It includes blind SQL injection and command execution capabilities via session manipulation.

Classification
Working Poc 95%
Attack Type
Sqli | Rce
Complexity
Moderate
Reliability
Reliable
Target: Centreon <= 2.5.4
No auth needed
Prerequisites: Network access to the target Centreon instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/37528

This is a detailed technical writeup describing two vulnerabilities in Centreon: an unauthenticated blind SQL injection (CVE-2015-1560) and an authenticated remote command execution (CVE-2015-1561). It includes proof-of-concept URLs, affected functions, and references to vendor fixes.

Classification
Writeup 100%
Attack Type
Sqli | Rce
Complexity
Moderate
Reliability
Reliable
Target: Merethis Centreon 2.5.4 and prior
No auth needed
Prerequisites: Network access to the target · Valid session_id for RCE exploitation
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

EPSS 0.0669
EPSS Percentile 93.0%

Details

CWE
CWE-89
Status published
Products (1)
centreon/centreon < 2.5.4
Published Jul 14, 2015
Tracked Since Feb 18, 2026