PT-2017-14294 · Artica · Artica Pandora Fms
Published
2017-10-27
·
Updated
2017-11-14
·
CVE-2017-15935
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Artica Pandora FMS version 7.0
Description
The issue allows for remote PHP code execution through the manager files function. This can only be exploited by administrators who upload a PHP file.
Recommendations
For Artica Pandora FMS version 7.0, restrict access to the manager files function to prevent unauthorized PHP file uploads until a fix is available. As a temporary workaround, consider disabling the ability for administrators to upload PHP files through this function.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Artica Pandora Fms