Vulnerabilities > Artica > Pandora FMS > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-11-23 CVE-2023-4677 Information Exposure Through Log Files vulnerability in Artica Pandora FMS
Cron log backup files contain administrator session IDs.
network
low complexity
artica CWE-532
critical
9.8
2023-11-23 CVE-2023-41790 Uncontrolled Search Path Element vulnerability in Artica Pandora FMS
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths.
network
low complexity
artica CWE-427
critical
9.8
2020-02-12 CVE-2020-8947 OS Command Injection vulnerability in Artica Pandora FMS 7.0
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224.
network
low complexity
artica CWE-78
critical
9.0
2020-01-09 CVE-2019-20224 OS Command Injection vulnerability in Artica Pandora FMS 7.0Ng
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request.
network
low complexity
artica CWE-78
critical
9.0
2017-10-27 CVE-2017-15935 Code Injection vulnerability in Artica Pandora FMS 7.0
Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function.
network
low complexity
artica CWE-94
critical
9.0
2010-12-02 CVE-2010-4279 Improper Authentication vulnerability in Artica Pandora FMS
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.
network
low complexity
artica CWE-287
critical
10.0
2010-12-02 CVE-2010-4278 OS Command Injection vulnerability in Artica Pandora FMS
operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php.
network
low complexity
artica CWE-78
critical
9.0