PT-2020-10329 · Artica · Pandora Fms
Published
2020-01-30
·
Updated
2020-08-24
·
CVE-2019-20050
CVSS v2.0
7.1
High
| Vector | AV:N/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Pandora FMS versions ≤ 7.42
Description
The issue allows for remote code execution. To exploit it, an authenticated user must create a new folder with a tricky name in the filemanager. The exploit is successful when the php-fileinfo extension is disabled on the host system. The attacker must include shell metacharacters in the content type.
Recommendations
For Pandora FMS versions ≤ 7.42, consider disabling the filemanager feature until a patch is available, and ensure the php-fileinfo extension is enabled on the host system to minimize the risk of exploitation.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pandora Fms