10

CVE-2010-4279

Exploit

The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.

Data is provided by the National Vulnerability Database (NVD)
ArticaPandora Fms Version <= 3.1
ArticaPandora Fms Version1.2
ArticaPandora Fms Version1.3
ArticaPandora Fms Version1.3 Updatebeta
ArticaPandora Fms Version1.3 Updatebeta1
ArticaPandora Fms Version1.3 Updatebeta2
ArticaPandora Fms Version1.3 Updatebeta3
ArticaPandora Fms Version1.3.1
ArticaPandora Fms Version2.0
ArticaPandora Fms Version2.0 Updatebeta
ArticaPandora Fms Version2.1
ArticaPandora Fms Version2.1.1
ArticaPandora Fms Version3.0
ArticaPandora Fms Version3.0 Updaterc1
ArticaPandora Fms Version3.0 Updaterc2
ArticaPandora Fms Version3.1 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 85.04% 0.993
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.