Pandorafms
by Artica
CVEs (78)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-34075 | Med | 0.38 | 5.9 | 0.01 | Jun 30, 2021 | In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access. | ||
| CVE-2023-41812 | Med | 0.37 | 5.7 | 0.01 | Nov 23, 2023 | Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allowed PHP executable files to be uploaded through the file manager. This issue affects Pandora FMS: from 700… | ||
| CVE-2026-30812 | Med | 0.35 | 5.4 | 0.00 | Apr 13, 2026 | Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800 | ||
| CVE-2021-36698 | Med | 0.35 | 5.4 | 0.01 | Nov 3, 2021 | Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name. | ||
| CVE-2020-13853 | Med | 0.35 | 5.4 | 0.01 | Jun 11, 2020 | Artica Pandora FMS 7.44 has persistent XSS in the Messages feature. | ||
| CVE-2020-8497 | Med | 0.35 | 5.3 | 0.05 | Mar 23, 2020 | In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps. | ||
| CVE-2018-11223 | Med | 0.35 | 5.4 | 0.01 | Jun 16, 2018 | XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call. | ||
| CVE-2017-15936 | Med | 0.35 | 5.4 | 0.01 | Oct 27, 2017 | In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed. | ||
| CVE-2017-15934 | Med | 0.35 | 5.4 | 0.01 | Oct 27, 2017 | Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site Scripting in the map name parameter. | ||
| CVE-2023-41811 | Med | 0.34 | 5.3 | 0.00 | Nov 23, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the news section of the web console. This issue affects… | ||
| CVE-2023-41810 | Med | 0.26 | 4.0 | 0.00 | Nov 23, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in some Widgets' text box. This issue affects Pandora FMS: from… | ||
| CVE-2021-46681 | Med | 0.26 | 4.0 | 0.00 | Aug 5, 2022 | A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field. | ||
| CVE-2010-4279 | 0.08 | — | 0.66 | Dec 2, 2010 | The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash… | |||
| CVE-2010-4282 | 0.05 | — | 0.20 | Dec 2, 2010 | Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and… | |||
| CVE-2010-4283 | 0.04 | — | 0.09 | Dec 2, 2010 | PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the argv[1] parameter. | |||
| CVE-2010-4281 | 0.04 | — | 0.10 | Dec 2, 2010 | Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code by using a page parameter containing a UNC share pathname, which bypasses the check for the : (colon) character. | |||
| CVE-2010-4278 | 0.04 | — | 0.11 | Dec 2, 2010 | operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php. | |||
| CVE-2010-4280 | 0.03 | — | 0.05 | Dec 2, 2010 | Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_group parameter in an operation/agentes/ver_agente action to ajax.php or (2) the group_id parameter in an… |
- risk 0.38cvss 5.9epss 0.01
In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.
- risk 0.37cvss 5.7epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allowed PHP executable files to be uploaded through the file manager. This issue affects Pandora FMS: from 700…
- risk 0.35cvss 5.4epss 0.00
Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800
- risk 0.35cvss 5.4epss 0.01
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
- risk 0.35cvss 5.4epss 0.01
Artica Pandora FMS 7.44 has persistent XSS in the Messages feature.
- risk 0.35cvss 5.3epss 0.05
In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.
- risk 0.35cvss 5.4epss 0.01
XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call.
- risk 0.35cvss 5.4epss 0.01
In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.
- risk 0.35cvss 5.4epss 0.01
Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site Scripting in the map name parameter.
- risk 0.34cvss 5.3epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the news section of the web console. This issue affects…
- risk 0.26cvss 4.0epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in some Widgets' text box. This issue affects Pandora FMS: from…
- risk 0.26cvss 4.0epss 0.00
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.
- CVE-2010-4279Dec 2, 2010risk 0.08cvss —epss 0.66
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash…
- CVE-2010-4282Dec 2, 2010risk 0.05cvss —epss 0.20
Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and…
- CVE-2010-4283Dec 2, 2010risk 0.04cvss —epss 0.09
PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the argv[1] parameter.
- CVE-2010-4281Dec 2, 2010risk 0.04cvss —epss 0.10
Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code by using a page parameter containing a UNC share pathname, which bypasses the check for the : (colon) character.
- CVE-2010-4278Dec 2, 2010risk 0.04cvss —epss 0.11
operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php.
- CVE-2010-4280Dec 2, 2010risk 0.03cvss —epss 0.05
Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_group parameter in an operation/agentes/ver_agente action to ajax.php or (2) the group_id parameter in an…
Page 4 of 4