CVE-2021-36697
- EPSS 0.24%
- Published 03.11.2021 12:15:07
- Last modified 21.11.2024 06:13:56
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file typ...
CVE-2021-34075
- EPSS 0.36%
- Published 30.06.2021 20:15:07
- Last modified 21.11.2024 06:09:52
In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.
CVE-2021-32100
- EPSS 0.51%
- Published 07.05.2021 04:15:07
- Last modified 21.11.2024 06:06:50
A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.
CVE-2021-32099
- EPSS 62.27%
- Published 07.05.2021 04:15:07
- Last modified 21.11.2024 06:06:50
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.
CVE-2021-32098
- EPSS 2.79%
- Published 07.05.2021 04:15:07
- Last modified 21.11.2024 06:06:50
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
CVE-2020-26518
- EPSS 3.38%
- Published 02.10.2020 05:15:12
- Last modified 21.11.2024 05:19:58
Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.
CVE-2020-8511
- EPSS 0.6%
- Published 23.03.2020 16:15:17
- Last modified 21.11.2024 05:38:58
In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a different issue than CVE-2020-7935 and CVE-2020-8500.
CVE-2020-7935
- EPSS 0.6%
- Published 23.03.2020 16:15:17
- Last modified 21.11.2024 05:38:02
Artica Pandora FMS through 7.42 is vulnerable to remote PHP code execution because of an Unrestricted Upload Of A File With A Dangerous Type issue in the File Manager. An attacker can create a (or use an existing) directory that is externally accessi...
CVE-2020-8497
- EPSS 34.66%
- Published 23.03.2020 15:15:14
- Last modified 21.11.2024 05:38:56
In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.
CVE-2020-5844
- EPSS 80.36%
- Published 16.03.2020 18:15:12
- Last modified 21.11.2024 05:34:41
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.