CVE-2021-36697
- EPSS 0.24%
- Veröffentlicht 03.11.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:56
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file typ...
CVE-2021-34075
- EPSS 0.36%
- Veröffentlicht 30.06.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:09:52
In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.
CVE-2021-32100
- EPSS 0.51%
- Veröffentlicht 07.05.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:50
A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.
CVE-2021-32099
- EPSS 62.27%
- Veröffentlicht 07.05.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:50
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.
CVE-2021-32098
- EPSS 2.79%
- Veröffentlicht 07.05.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:50
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
CVE-2020-26518
- EPSS 3.38%
- Veröffentlicht 02.10.2020 05:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:58
Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.
CVE-2020-8511
- EPSS 0.6%
- Veröffentlicht 23.03.2020 16:15:17
- Zuletzt bearbeitet 21.11.2024 05:38:58
In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a different issue than CVE-2020-7935 and CVE-2020-8500.
CVE-2020-7935
- EPSS 0.6%
- Veröffentlicht 23.03.2020 16:15:17
- Zuletzt bearbeitet 21.11.2024 05:38:02
Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in the File Manager. An attacker can create a (or use an existing) directory that is externally accessi...
CVE-2020-8497
- EPSS 34.66%
- Veröffentlicht 23.03.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:38:56
In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.
CVE-2020-5844
- EPSS 80.36%
- Veröffentlicht 16.03.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:41
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.