Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
artica pandora fms vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2018-11221
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an malicious user to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.
Artica Pandora Fms
7.5
CVSSv3
CVE-2018-11222
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an malicious user to call any php file via the /pandora_console/ajax.php ajax endpoint.
Artica Pandora Fms
5.4
CVSSv3
CVE-2018-11223
XSS in Artica Pandora FMS prior to 7.0 NG 723 allows an malicious user to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call.
Pandorafms Artica Pandora Fms
5.4
CVSSv3
CVE-2017-15934
Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site Scripting in the map name parameter.
Artica Pandora Fms 7.0
5.4
CVSSv3
CVE-2017-15936
In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.
Artica Pandora Fms 7.0
7.2
CVSSv3
CVE-2017-15935
Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrators who upload a PHP file.
Artica Pandora Fms 7.0
6.5
CVSSv3
CVE-2017-15937
Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition. This also implies that general OS information is leaked (e.g., a /var/www pathname typically means Linux or UNIX).
Artica Pandora Fms 7.0
NA
CVE-2010-4280
Multiple SQL injection vulnerabilities in Pandora FMS prior to 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_group parameter in an operation/agentes/ver_agente action to ajax.php or (2) the group_id parameter in an operation/agentes/estad...
Artica Pandora Fms 3.0
Artica Pandora Fms 3.1
Artica Pandora Fms 2.0
Artica Pandora Fms 2.1.1
Artica Pandora Fms 1.3.1
Artica Pandora Fms 1.3
Artica Pandora Fms 2.1
Artica Pandora Fms 1.2
Artica Pandora Fms
2 EDB exploits
NA
CVE-2010-4281
Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS prior to 3.1.1 allows remote malicious users to execute arbitrary PHP code by using a page parameter containing a UNC share pathname, which bypasses the check for the : (colon) chara...
Artica Pandora Fms 3.0
Artica Pandora Fms 3.1
Artica Pandora Fms
Artica Pandora Fms 2.0
Artica Pandora Fms 2.1
Artica Pandora Fms 2.1.1
Artica Pandora Fms 1.3
Artica Pandora Fms 1.3.1
Artica Pandora Fms 1.2
1 EDB exploit
NA
CVE-2010-4283
PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS prior to 3.1.1 allows remote malicious users to execute arbitrary PHP code via a URL in the argv[1] parameter.
Artica Pandora Fms 3.0
Artica Pandora Fms 3.1
Artica Pandora Fms
Artica Pandora Fms 2.0
Artica Pandora Fms 2.1
Artica Pandora Fms 2.1.1
Artica Pandora Fms 1.3
Artica Pandora Fms 1.3.1
Artica Pandora Fms 1.2
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »