CVE-2021-35501
- EPSS 1%
- Veröffentlicht 25.06.2021 16:15:17
- Zuletzt bearbeitet 21.11.2024 06:12:23
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.
- EPSS 16.23%
- Veröffentlicht 13.07.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:58:32
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as ro...
- EPSS 27.63%
- Veröffentlicht 11.06.2020 03:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:00
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.
- EPSS 2.96%
- Veröffentlicht 11.06.2020 03:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:00
Artica Pandora FMS 7.44 allows privilege escalation.
CVE-2020-13853
- EPSS 1.04%
- Veröffentlicht 11.06.2020 03:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:00
Artica Pandora FMS 7.44 has persistent XSS in the Messages feature.
- EPSS 27.63%
- Veröffentlicht 11.06.2020 03:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:00
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
- EPSS 91.1%
- Veröffentlicht 11.06.2020 03:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:00
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
CVE-2020-13850
- EPSS 2.17%
- Veröffentlicht 11.06.2020 03:15:09
- Zuletzt bearbeitet 21.11.2024 05:02:00
Artica Pandora FMS 7.44 has inadequate access controls on a web folder.
CVE-2019-19968
- EPSS 0.8%
- Veröffentlicht 04.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:46
PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic co...
CVE-2019-13035
- EPSS 0.39%
- Veröffentlicht 29.06.2019 13:15:08
- Zuletzt bearbeitet 21.11.2024 04:24:05
Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, the Apache service httpd.exe will try to execute cmd...