Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
artica vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2010-4280
Multiple SQL injection vulnerabilities in Pandora FMS prior to 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_group parameter in an operation/agentes/ver_agente action to ajax.php or (2) the group_id parameter in an operation/agentes/estad...
Artica Pandora Fms 3.0
Artica Pandora Fms 3.1
Artica Pandora Fms 2.0
Artica Pandora Fms 2.1.1
Artica Pandora Fms 1.3.1
Artica Pandora Fms 1.3
Artica Pandora Fms 2.1
Artica Pandora Fms 1.2
Artica Pandora Fms
2 EDB exploits
NA
CVE-2010-4281
Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS prior to 3.1.1 allows remote malicious users to execute arbitrary PHP code by using a page parameter containing a UNC share pathname, which bypasses the check for the : (colon) chara...
Artica Pandora Fms 3.0
Artica Pandora Fms 3.1
Artica Pandora Fms
Artica Pandora Fms 2.0
Artica Pandora Fms 2.1
Artica Pandora Fms 2.1.1
Artica Pandora Fms 1.3
Artica Pandora Fms 1.3.1
Artica Pandora Fms 1.2
1 EDB exploit
NA
CVE-2010-4283
PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS prior to 3.1.1 allows remote malicious users to execute arbitrary PHP code via a URL in the argv[1] parameter.
Artica Pandora Fms 3.0
Artica Pandora Fms 3.1
Artica Pandora Fms
Artica Pandora Fms 2.0
Artica Pandora Fms 2.1
Artica Pandora Fms 2.1.1
Artica Pandora Fms 1.3
Artica Pandora Fms 1.3.1
Artica Pandora Fms 1.2
1 EDB exploit
NA
CVE-2010-4278
operation/agentes/networkmap.php in Pandora FMS prior to 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php.
Artica Pandora Fms 3.1
Artica Pandora Fms 3.0
Artica Pandora Fms 2.0
Artica Pandora Fms 2.1.1
Artica Pandora Fms 1.3.1
Artica Pandora Fms 1.3
Artica Pandora Fms 2.1
Artica Pandora Fms 1.2
Artica Pandora Fms
1 EDB exploit
NA
CVE-2010-4279
The default configuration of Pandora FMS 3.1 and previous versions specifies an empty string for the loginhash_pwd field, which allows remote malicious users to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conj...
Artica Pandora Fms 3.1
Artica Pandora Fms 3.0
Artica Pandora Fms 2.0
Artica Pandora Fms 2.1.1
Artica Pandora Fms 1.3.1
Artica Pandora Fms 1.3
Artica Pandora Fms 2.1
Artica Pandora Fms 1.2
Artica Pandora Fms
2 EDB exploits
NA
CVE-2010-4282
Multiple directory traversal vulnerabilities in Pandora FMS prior to 3.1.1 allow remote malicious users to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote malicious users to inc...
Artica Pandora Fms 3.0
Artica Pandora Fms 3.1
Artica Pandora Fms
Artica Pandora Fms 2.0
Artica Pandora Fms 2.1
Artica Pandora Fms 2.1.1
Artica Pandora Fms 1.3
Artica Pandora Fms 1.3.1
Artica Pandora Fms 1.2
1 EDB exploit
9.8
CVSSv3
CVE-2021-41739
A OS Command Injection vulnerability exists in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
Artica-proxy Artica Proxy 4.30.000000
9.8
CVSSv3
CVE-2023-4677
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an admini...
Artica Pandora Fms
9
CVSSv3
CVE-2017-17055
Artica Web Proxy prior to 3.06.112911 allows remote malicious users to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.
Articatech Artica Proxy
1 EDB exploit
6.7
CVSSv3
CVE-2021-36697
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code c...
Artica Pandora Fms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »