Pandora FMS
cpe:2.3:a:pandorafms:pandora_fms:*:*:*:*:*:*:*
- >= 777, <= 800
A vulnerability in Pandora FMS versions 777 through 800 allows for unrestricted file uploads of dangerous file types, leading to remote code execution. This issue arises from the File Repository Manager feature, where authenticated administrators can upload malicious PHP scripts and execute them by decoding the file location.
Exploitation of this vulnerability allows for remote code execution on the server where Pandora FMS is running.
To reproduce this vulnerability, an authenticated administrator can upload a PHP file through the File Repository Manager. The uploaded file can then be executed by accessing its location on the server, provided the php-fileinfo extension is disabled.
Users can update to Pandora FMS version 801 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.