VendorsArticapandora_fms7.42
Vulnerabilities

Artica Pandora FMS 7.42

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-8500
In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality
Published 2020-03-02 · Modified
7.2EPSS 0.035
CVE-2019-20050
Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder with a "tricky" name in the filemanager. The exploit works when the php-fileinfo extension is disabled on the host system. The attacker must include shell metacharacters in the content type.
Published 2020-01-30 · Modified
7.1EPSS 0.034