Show filters
47 Total Results
Displaying 31-40 of 47
Sort by:
Attacker Value
Unknown

CVE-2021-46676

Disclosure Date: February 21, 2022 (last updated October 08, 2023)
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field.
Attacker Value
Unknown

CVE-2021-46677

Disclosure Date: February 21, 2022 (last updated October 08, 2023)
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field.
Attacker Value
Unknown

CVE-2021-46678

Disclosure Date: February 21, 2022 (last updated October 08, 2023)
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field.
Attacker Value
Unknown

CVE-2021-46679

Disclosure Date: February 21, 2022 (last updated October 08, 2023)
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.
Attacker Value
Unknown

CVE-2022-0507

Disclosure Date: February 10, 2022 (last updated November 08, 2023)
Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.
Attacker Value
Unknown

CVE-2021-34074

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
Attacker Value
Unknown

CVE-2020-11749

Disclosure Date: July 13, 2020 (last updated February 21, 2025)
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
Attacker Value
Unknown

CVE-2020-13852

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
Attacker Value
Unknown

CVE-2020-13850

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Artica Pandora FMS 7.44 has inadequate access controls on a web folder.
Attacker Value
Unknown

CVE-2020-13851

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Artica Pandora FMS 7.44 allows remote command execution via the events feature.