Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2020-5844
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.
0
Attacker Value
Unknown
CVE-2020-8947
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224.
0
Attacker Value
Unknown
CVE-2019-19681
Disclosure Date: December 26, 2019 (last updated November 08, 2023)
Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in fact an actual vulnerability. They state that to be able to create alert commands, you need to have admin rights. They also state that the extended ACL system can disable access to specific sections of the configuration, such as defining new alert commands
0
Attacker Value
Unknown
CVE-2019-20224
Disclosure Date: June 19, 2019 (last updated February 21, 2025)
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
0
Attacker Value
Unknown
CVE-2017-15934
Disclosure Date: October 27, 2017 (last updated November 26, 2024)
Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site Scripting in the map name parameter.
0
Attacker Value
Unknown
CVE-2017-15935
Disclosure Date: October 27, 2017 (last updated November 26, 2024)
Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrators who upload a PHP file.
0
Attacker Value
Unknown
CVE-2017-15937
Disclosure Date: October 27, 2017 (last updated November 26, 2024)
Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition. This also implies that general OS information is leaked (e.g., a /var/www pathname typically means Linux or UNIX).
0
Attacker Value
Unknown
CVE-2017-15936
Disclosure Date: October 27, 2017 (last updated November 26, 2024)
In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.
0