Vulnerabilities (CVE)

Filtered by vendor Artica Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-4677 1 Artica 1 Pandora Fms 2023-11-30 N/A 9.8 CRITICAL
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an administrator. This issue affects Pandora FMS <= 772.
CVE-2023-41790 1 Artica 1 Pandora Fms 2023-11-29 N/A 9.8 CRITICAL
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows to access the server configuration file and to compromise the database. This issue affects Pandora FMS: from 700 through 773.
CVE-2021-3833 1 Artica 1 Integria Ims 2023-11-20 7.5 HIGH 9.8 CRITICAL
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with different passwords.
CVE-2021-3832 1 Artica 1 Integria Ims 2021-10-15 7.5 HIGH 9.8 CRITICAL
Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.
CVE-2021-32099 1 Artica 1 Pandora Fms 2021-05-11 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.
CVE-2021-32098 1 Artica 1 Pandora Fms 2021-05-11 7.5 HIGH 9.8 CRITICAL
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
CVE-2020-26518 1 Artica 1 Pandora Fms 2020-10-09 7.5 HIGH 9.8 CRITICAL
Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.
CVE-2019-15091 1 Artica 1 Integria Ims 2019-08-27 7.5 HIGH 9.8 CRITICAL
filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.
CVE-2018-11221 1 Artica 1 Pandora Fms 2018-08-14 7.5 HIGH 9.8 CRITICAL
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.