Total
30 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-13851 | 1 Pandorafms | 1 Pandora Fms | 2022-04-27 | 9.0 HIGH | 8.8 HIGH |
Artica Pandora FMS 7.44 allows remote command execution via the events feature. | |||||
CVE-2021-35501 | 1 Pandorafms | 1 Pandora Fms | 2021-09-14 | 3.5 LOW | 5.4 MEDIUM |
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed. | |||||
CVE-2020-13850 | 1 Pandorafms | 1 Pandora Fms | 2021-07-21 | 5.0 MEDIUM | 7.5 HIGH |
Artica Pandora FMS 7.44 has inadequate access controls on a web folder. | |||||
CVE-2021-34074 | 1 Pandorafms | 1 Pandora Fms | 2021-07-01 | 7.5 HIGH | 9.8 CRITICAL |
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests. | |||||
CVE-2019-13035 | 1 Pandorafms | 1 Pandora Fms | 2020-08-24 | 7.2 HIGH | 7.8 HIGH |
Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, the Apache service httpd.exe will try to execute cmd.exe from C:\PandoraFMS (the current directory) as NT AUTHORITY\SYSTEM upon web requests to the portal. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM. | |||||
CVE-2020-13852 | 1 Pandorafms | 1 Pandora Fms | 2020-06-11 | 9.0 HIGH | 7.2 HIGH |
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature. | |||||
CVE-2020-13853 | 1 Pandorafms | 1 Pandora Fms | 2020-06-11 | 3.5 LOW | 5.4 MEDIUM |
Artica Pandora FMS 7.44 has persistent XSS in the Messages feature. | |||||
CVE-2020-13854 | 1 Pandorafms | 1 Pandora Fms | 2020-06-11 | 10.0 HIGH | 9.8 CRITICAL |
Artica Pandora FMS 7.44 allows privilege escalation. | |||||
CVE-2020-13855 | 1 Pandorafms | 1 Pandora Fms | 2020-06-11 | 9.0 HIGH | 7.2 HIGH |
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature. | |||||
CVE-2019-19968 | 1 Pandorafms | 1 Pandora Fms | 2020-02-05 | 3.5 LOW | 5.4 MEDIUM |
PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content. |