CVE-2015-1560

Centreon <2.5.4 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to include/common/XmlTree/GetXmlTree.php.

Exploits (2)

nomisec WORKING POC 3 stars
by Iansus · poc
https://github.com/Iansus/Centreon-CVE-2015-1560_1561
exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/37528

Scores

EPSS 0.0298
EPSS Percentile 86.6%

Details

CWE
CWE-89
Status published
Products (1)
centreon/centreon < 2.5.4
Published Jul 14, 2015
Tracked Since Feb 18, 2026