Show filters
97 Total Results
Displaying 1-10 of 97
Sort by:
Attacker Value
Very High
CVE-2024-11320
Disclosure Date: November 21, 2024 (last updated December 21, 2024)
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
1
Attacker Value
Moderate
CVE-2021-35501
Disclosure Date: June 25, 2021 (last updated February 22, 2025)
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.
1
Attacker Value
Low
CVE-2020-8500
Disclosure Date: March 02, 2020 (last updated February 21, 2025)
In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality
0
Attacker Value
Unknown
CVE-2024-9987
Disclosure Date: October 22, 2024 (last updated October 26, 2024)
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.
0
Attacker Value
Unknown
CVE-2024-35308
Disclosure Date: October 22, 2024 (last updated October 26, 2024)
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.
0
Attacker Value
Unknown
CVE-2024-35307
Disclosure Date: June 10, 2024 (last updated June 11, 2024)
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.
0
Attacker Value
Unknown
CVE-2024-35306
Disclosure Date: June 10, 2024 (last updated June 11, 2024)
OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.
0
Attacker Value
Unknown
CVE-2024-35305
Disclosure Date: June 10, 2024 (last updated June 11, 2024)
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
0
Attacker Value
Unknown
CVE-2024-35304
Disclosure Date: June 10, 2024 (last updated June 11, 2024)
System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.
0
Attacker Value
Unknown
CVE-2023-44092
Disclosure Date: March 19, 2024 (last updated April 01, 2024)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776.
0