Summary
Pandora FMS is prone to an authentication-bypass vulnerability as well as the following input-validation vulnerabilities:
1. A command-injection vulnerability
2. Multiple SQL-injection vulnerabilities
3. A remote file-include vulnerability
4. An arbitrary PHP-code-execution vulnerability
5. Multiple local file-include vulnerabilities
Attackers may exploit these issues to execute local and remote script code in the context of the affected application, compromise the application, obtain sensitive information, access or modify data, exploit latent vulnerabilities in the underlying database, and gain administrative access to the affected application.
Versions prior and including Pandora FMS 3.1 are vulnerable.
Solution
Updates are available. Please see the reference for more details.
References
Severity
Classification
-
CVE CVE-2010-4278, CVE-2010-4279, CVE-2010-4280, CVE-2010-4281, CVE-2010-4282, CVE-2010-4283 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities