CVE-2010-4282
Pandora Fms 3.1 - Directory Traversal / Local File Inclusion
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.
Múltiples vulnerabilidades de salto de directorio en FMS anterior a v3.1.1 permite a atacantes remotos incluir y ejecutar ficheros locales de su elección mediante (1) el parámetro page para ajax.php o (2) el parámetro id para general/pandora_help.php, y permite a atacantes remotos incluir, ejecutar, crear, modificar, o borrar ficheros locales de su elección mediante (3) el parámetro layout para operation/agentes/networkmap.php.
Pandora FMS versions 3.1 and below suffer from authentication bypass, os command injection, remote SQL injection, remote file inclusion and path traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-11-17 CVE Reserved
- 2010-11-30 First Exploit
- 2010-12-01 CVE Published
- 2024-06-12 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://osvdb.org/69543 | Vdb Entry | |
http://osvdb.org/69544 | Vdb Entry | |
http://osvdb.org/69545 | Vdb Entry | |
http://seclists.org/fulldisclosure/2010/Nov/326 | Mailing List | |
http://secunia.com/advisories/42347 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/514939/100/0/threaded | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/15643 | 2010-11-30 | |
http://www.exploit-db.com/exploits/15643 | 2024-08-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | <= 3.1 Search vendor "Artica" for product "Pandora Fms" and version " <= 3.1" | - |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 1.2 Search vendor "Artica" for product "Pandora Fms" and version "1.2" | - |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 1.3 Search vendor "Artica" for product "Pandora Fms" and version "1.3" | - |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 1.3 Search vendor "Artica" for product "Pandora Fms" and version "1.3" | beta |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 1.3 Search vendor "Artica" for product "Pandora Fms" and version "1.3" | beta1 |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 1.3 Search vendor "Artica" for product "Pandora Fms" and version "1.3" | beta2 |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 1.3 Search vendor "Artica" for product "Pandora Fms" and version "1.3" | beta3 |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 1.3.1 Search vendor "Artica" for product "Pandora Fms" and version "1.3.1" | - |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 2.0 Search vendor "Artica" for product "Pandora Fms" and version "2.0" | - |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 2.0 Search vendor "Artica" for product "Pandora Fms" and version "2.0" | beta |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 2.1 Search vendor "Artica" for product "Pandora Fms" and version "2.1" | - |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 2.1.1 Search vendor "Artica" for product "Pandora Fms" and version "2.1.1" | - |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 3.0 Search vendor "Artica" for product "Pandora Fms" and version "3.0" | - |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 3.0 Search vendor "Artica" for product "Pandora Fms" and version "3.0" | rc1 |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 3.0 Search vendor "Artica" for product "Pandora Fms" and version "3.0" | rc2 |
Affected
| ||||||
Artica Search vendor "Artica" | Pandora Fms Search vendor "Artica" for product "Pandora Fms" | 3.1 Search vendor "Artica" for product "Pandora Fms" and version "3.1" | rc1 |
Affected
|