Vulnerabilities > Artica > Pandora FMS > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-05-07 CVE-2021-32100 Unspecified vulnerability in Artica Pandora FMS 742
A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.
network
low complexity
artica
6.5
2020-03-23 CVE-2020-8497 Missing Authentication for Critical Function vulnerability in Artica Pandora FMS
In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history.
network
low complexity
artica CWE-306
5.3
2020-01-30 CVE-2019-20050 OS Command Injection vulnerability in Artica Pandora FMS 7.42
Pandora FMS = 7.42 suffers from a remote code execution vulnerability.
network
low complexity
artica CWE-78
6.8
2017-10-27 CVE-2017-15937 Information Exposure vulnerability in Artica Pandora FMS 7.0
Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition.
network
low complexity
artica CWE-200
6.5
2017-10-27 CVE-2017-15936 Cross-site Scripting vulnerability in Artica Pandora FMS 7.0
In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.
network
low complexity
artica CWE-79
5.4
2017-10-27 CVE-2017-15934 Cross-site Scripting vulnerability in Artica Pandora FMS 7.0
Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site Scripting in the map name parameter.
network
low complexity
artica CWE-79
5.4