PT-2020-10329 · Artica · Pandora Fms

Published

2020-01-30

·

Updated

2020-08-24

·

CVE-2019-20050

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pandora FMS versions ≤ 7.42
Description The issue allows for remote code execution. To exploit it, an authenticated user must create a new folder with a tricky name in the filemanager. The exploit is successful when the php-fileinfo extension is disabled on the host system. The attacker must include shell metacharacters in the content type.
Recommendations For Pandora FMS versions ≤ 7.42, consider disabling the filemanager feature until a patch is available, and ensure the php-fileinfo extension is enabled on the host system to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20050

Affected Products

Pandora Fms