Vulnerabilities
Vulnerable Software
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.
CVSS Score
9.8
EPSS Score
0.036
Published
2021-06-25
PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the console, the XSS payload will be executed.
CVSS Score
5.4
EPSS Score
0.004
Published
2021-06-25
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
CVSS Score
9.0
EPSS Score
0.049
Published
2020-07-13


Contact Us

Shodan ® - All rights reserved