PT-2017-14294 · Artica · Artica Pandora Fms
Publicado
2017-10-27
·
Atualizado
2017-11-14
·
CVE-2017-15935
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Artica Pandora FMS version 7.0
Description
The issue allows for remote PHP code execution through the manager files function. This can only be exploited by administrators who upload a PHP file.
Recommendations
For Artica Pandora FMS version 7.0, restrict access to the manager files function to prevent unauthorized PHP file uploads until a fix is available. As a temporary workaround, consider disabling the ability for administrators to upload PHP files through this function.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Artica Pandora Fms