VYPR

Pandorafms

by Artica

CVEs (78)

  • CVE-2021-34075MedJun 30, 2021
    risk 0.38cvss 5.9epss 0.01

    In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.

  • CVE-2023-41812MedNov 23, 2023
    risk 0.37cvss 5.7epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allowed PHP executable files to be uploaded through the file manager. This issue affects Pandora FMS: from 700…

  • CVE-2026-30812MedApr 13, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800

  • CVE-2021-36698MedNov 3, 2021
    risk 0.35cvss 5.4epss 0.01

    Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

  • CVE-2020-13853MedJun 11, 2020
    risk 0.35cvss 5.4epss 0.01

    Artica Pandora FMS 7.44 has persistent XSS in the Messages feature.

  • CVE-2020-8497MedMar 23, 2020
    risk 0.35cvss 5.3epss 0.05

    In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.

  • CVE-2018-11223MedJun 16, 2018
    risk 0.35cvss 5.4epss 0.01

    XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call.

  • CVE-2017-15936MedOct 27, 2017
    risk 0.35cvss 5.4epss 0.01

    In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.

  • CVE-2017-15934MedOct 27, 2017
    risk 0.35cvss 5.4epss 0.01

    Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site Scripting in the map name parameter.

  • CVE-2023-41811MedNov 23, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the news section of the web console. This issue affects…

  • CVE-2023-41810MedNov 23, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in some Widgets' text box. This issue affects Pandora FMS: from…

  • CVE-2021-46681MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.

  • CVE-2010-4279Dec 2, 2010
    risk 0.08cvss epss 0.66

    The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash…

  • CVE-2010-4282Dec 2, 2010
    risk 0.05cvss epss 0.20

    Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and…

  • CVE-2010-4283Dec 2, 2010
    risk 0.04cvss epss 0.09

    PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the argv[1] parameter.

  • CVE-2010-4281Dec 2, 2010
    risk 0.04cvss epss 0.10

    Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code by using a page parameter containing a UNC share pathname, which bypasses the check for the : (colon) character.

  • CVE-2010-4278Dec 2, 2010
    risk 0.04cvss epss 0.11

    operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php.

  • CVE-2010-4280Dec 2, 2010
    risk 0.03cvss epss 0.05

    Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_group parameter in an operation/agentes/ver_agente action to ajax.php or (2) the group_id parameter in an…

Page 4 of 4