← All CVEs

CVE-2010-4278

high · 9

operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php.

9
CVSS
11.3%
EPSS (exploit prob.)
96th
EPSS percentile
2010-12-02
Published

AV:N/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
articapandora_fms<= 3.1
articapandora_fms1.2
articapandora_fms1.3
articapandora_fms1.3
articapandora_fms1.3
articapandora_fms1.3
articapandora_fms1.3
articapandora_fms1.3.1
articapandora_fms2.0
articapandora_fms2.0
articapandora_fms2.1
articapandora_fms2.1.1
articapandora_fms3.0
articapandora_fms3.0
articapandora_fms3.0
articapandora_fms3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-4278