High severity7.2NVD Advisory· Published Mar 2, 2020· Updated Jun 17, 2026
CVE-2020-8500
CVE-2020-8500
Description
In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
37.42+ 1 more
- (no CPE)range: 7.42
- cpe:2.3:a:artica:pandora_fms:7.42:*:*:*:*:*:*:*
- Artica/Pandora FMSdescription
Patches
Vulnerability mechanics
References
2- k4m1ll0.com/cve-2020-8500.htmlnvdExploitThird Party Advisory
- pandorafms.com/downloads/extension-uploader-feature-explained.mp4nvd
News mentions
0No linked articles in our index yet.