Centreon 2.5.1、Centreon Enterprise Server 2.2存在多个sql注入漏洞,远程攻击者通过views/graphs/common/makeXML_ListMetrics.php的index_id参数,s/graphs/GetXmlTree.php的sid参数,views/graphs/graphStatus/displayServiceStatus.php的session_id参数,configuration/configObject/traps/GetXMLTrapsForVendor.php的mnftr_id参数,common/javascript/commandGetArgs/cmdGetExample.php的index参数,利用此漏洞可执行任意sql命令。