Vulnerabilities (CVE)

Filtered by vendor Pandorafms Subscribe
Filtered by product Pandora Fms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-44088 1 Pandorafms 1 Pandora Fms 2024-01-05 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.
CVE-2020-13851 1 Pandorafms 1 Pandora Fms 2022-04-27 9.0 HIGH 8.8 HIGH
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
CVE-2020-13850 1 Pandorafms 1 Pandora Fms 2021-07-21 5.0 MEDIUM 7.5 HIGH
Artica Pandora FMS 7.44 has inadequate access controls on a web folder.
CVE-2019-13035 1 Pandorafms 1 Pandora Fms 2020-08-24 7.2 HIGH 7.8 HIGH
Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, the Apache service httpd.exe will try to execute cmd.exe from C:\PandoraFMS (the current directory) as NT AUTHORITY\SYSTEM upon web requests to the portal. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM.
CVE-2020-13852 1 Pandorafms 1 Pandora Fms 2020-06-11 9.0 HIGH 7.2 HIGH
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.
CVE-2020-13855 1 Pandorafms 1 Pandora Fms 2020-06-11 9.0 HIGH 7.2 HIGH
Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Repository Manager feature.