Show filters
97 Total Results
Displaying 71-80 of 97
Sort by:
Attacker Value
Unknown

CVE-2020-13851

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
Attacker Value
Unknown

CVE-2020-13855

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.
Attacker Value
Unknown

CVE-2020-13853

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Artica Pandora FMS 7.44 has persistent XSS in the Messages feature.
Attacker Value
Unknown

CVE-2020-13854

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Artica Pandora FMS 7.44 allows privilege escalation.
Attacker Value
Unknown

CVE-2020-7935

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in the File Manager. An attacker can create a (or use an existing) directory that is externally accessible to store PHP files. The filename and the exact path is known by the attacker, so it is possible to execute PHP code in the context of the application. The vulnerability is exploitable only with Administrator access.
Attacker Value
Unknown

CVE-2020-8511

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a different issue than CVE-2020-7935 and CVE-2020-8500.
Attacker Value
Unknown

CVE-2020-8497

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.
Attacker Value
Unknown

CVE-2020-5844

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.
Attacker Value
Unknown

CVE-2020-8947

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224.
Attacker Value
Unknown

CVE-2019-19968

Disclosure Date: February 04, 2020 (last updated February 21, 2025)
PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content.