← All CVEs

CVE-2010-4279

high · 10

The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.

10
CVSS
65.6%
EPSS (exploit prob.)
99th
EPSS percentile
2010-12-02
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
articapandora_fms<= 3.1
articapandora_fms1.2
articapandora_fms1.3
articapandora_fms1.3
articapandora_fms1.3
articapandora_fms1.3
articapandora_fms1.3
articapandora_fms1.3.1
articapandora_fms2.0
articapandora_fms2.0
articapandora_fms2.1
articapandora_fms2.1.1
articapandora_fms3.0
articapandora_fms3.0
articapandora_fms3.0
articapandora_fms3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-4279