Show filters
97 Total Results
Displaying 61-70 of 97
Sort by:
Attacker Value
Unknown

CVE-2021-36698

Disclosure Date: November 03, 2021 (last updated February 23, 2025)
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
Attacker Value
Unknown

CVE-2021-34075

Disclosure Date: June 30, 2021 (last updated February 22, 2025)
In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.
Attacker Value
Unknown

CVE-2021-34074

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
Attacker Value
Unknown

CVE-2021-32098

Disclosure Date: May 07, 2021 (last updated February 22, 2025)
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
Attacker Value
Unknown

CVE-2021-32099

Disclosure Date: May 07, 2021 (last updated February 22, 2025)
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.
Attacker Value
Unknown

CVE-2021-32100

Disclosure Date: May 07, 2021 (last updated February 22, 2025)
A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.
Attacker Value
Unknown

CVE-2020-26518

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.
Attacker Value
Unknown

CVE-2020-11749

Disclosure Date: July 13, 2020 (last updated February 21, 2025)
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
Attacker Value
Unknown

CVE-2020-13852

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
Attacker Value
Unknown

CVE-2020-13850

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Artica Pandora FMS 7.44 has inadequate access controls on a web folder.