Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
artica vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2023-41812
Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allowed PHP executable files to be uploaded through the file manager. This issue affects Pandora FMS: from 700 u...
Artica Pandora Fms
8.1
CVSSv3
CVE-2018-1000812
Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 45 of general/password_recovery.php that can result in IntegriaIMS web app user ac...
Artica Integria Ims
9.8
CVSSv3
CVE-2018-11221
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an malicious user to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.
Artica Pandora Fms
7.5
CVSSv3
CVE-2018-11222
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an malicious user to call any php file via the /pandora_console/ajax.php ajax endpoint.
Artica Pandora Fms
9
CVSSv3
CVE-2017-17055
Artica Web Proxy prior to 3.06.112911 allows remote malicious users to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.
Articatech Artica Proxy
1 EDB exploit
9.8
CVSSv3
CVE-2020-26518
Artica Pandora FMS prior to 743 allows unauthenticated malicious users to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.
Artica Pandora Fms
7.5
CVSSv3
CVE-2020-13158
Artica Proxy prior to 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
Articatech Artica Proxy
1 Github repository
9.8
CVSSv3
CVE-2020-13159
Artica Proxy prior to 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.
Articatech Artica Proxy
1 Github repository
6.7
CVSSv3
CVE-2021-36697
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code c...
Artica Pandora Fms
5.4
CVSSv3
CVE-2021-36698
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
Artica Pandora Fms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »