displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.
| Software | From | Fixed in |
|---|---|---|
| merethis / centreon | 2.5.1 | 2.5.1.x |
| merethis / centreon_enterprise_server | 2.2 | 2.2.x |