Unrated severityNVD Advisory· Published Dec 2, 2010· Updated Apr 29, 2026
CVE-2010-4279
CVE-2010-4279
Description
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.
Affected products
16cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:*range: <=3.1
- cpe:2.3:a:artica:pandora_fms:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:1.3:beta:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:1.3:beta1:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:1.3:beta2:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:1.3:beta3:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:2.0:beta:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:3.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:3.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:artica:pandora_fms:3.1:rc1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- sourceforge.net/projects/pandora/files/Pandora%20FMS%203.1/Final%20version%20%28Stable%29/pandorafms_console-3.1_security_patch_13Oct2010.tar.gz/downloadnvdPatch
- www.exploit-db.com/exploits/15639nvdExploit
- www.securityfocus.com/bid/45112nvdExploitPatch
- osvdb.org/69549nvd
- packetstormsecurity.com/files/129830/Pandora-3.1-Auth-Bypass-Arbitrary-File-Upload.htmlnvd
- seclists.org/fulldisclosure/2010/Nov/326nvd
- secunia.com/advisories/42347nvd
- www.securityfocus.com/archive/1/514939/100/0/threadednvd
- www.exploit-db.com/exploits/35731/nvd
News mentions
0No linked articles in our index yet.