Artica

Pandora Fms

70 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.54%
  • Veröffentlicht 23.11.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 08:21:41

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. This vulnerability allows users with low privileges to download database backups. This issue affects Pandora FMS: from 700 through 7...

  • EPSS 0.33%
  • Veröffentlicht 05.08.2022 16:15:11
  • Zuletzt bearbeitet 21.11.2024 06:34:35

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.

Exploit
  • EPSS 0.73%
  • Veröffentlicht 03.11.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:13:56

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 03.11.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:13:56

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file typ...

Exploit
  • EPSS 0.92%
  • Veröffentlicht 30.06.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:09:52

In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.

Exploit
  • EPSS 2.59%
  • Veröffentlicht 07.05.2021 04:15:07
  • Zuletzt bearbeitet 21.11.2024 06:06:50

A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.

Exploit
  • EPSS 11.39%
  • Veröffentlicht 07.05.2021 04:15:07
  • Zuletzt bearbeitet 21.11.2024 06:06:50

A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.

Exploit
  • EPSS 2.47%
  • Veröffentlicht 07.05.2021 04:15:07
  • Zuletzt bearbeitet 21.11.2024 06:06:50

Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.

Exploit
  • EPSS 2.03%
  • Veröffentlicht 02.10.2020 05:15:12
  • Zuletzt bearbeitet 21.11.2024 05:19:58

Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.

Exploit
  • EPSS 3.08%
  • Veröffentlicht 23.03.2020 16:15:17
  • Zuletzt bearbeitet 21.11.2024 05:38:58

In Artica Pandora FMS through 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the File Repository component, a different issue than CVE-2020-7935 and CVE-2020-8500.