CVE-2010-4282

Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:1.2:*:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:1.3:*:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:1.3:beta:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:1.3:beta1:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:1.3:beta2:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:1.3:beta3:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:2.0:*:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:2.0:beta:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:2.1:*:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:3.0:*:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:artica:pandora_fms:3.1:rc1:*:*:*:*:*:*

History

21 Nov 2024, 01:20

Type Values Removed Values Added
References () http://osvdb.org/69543 - () http://osvdb.org/69543 -
References () http://osvdb.org/69544 - () http://osvdb.org/69544 -
References () http://osvdb.org/69545 - () http://osvdb.org/69545 -
References () http://seclists.org/fulldisclosure/2010/Nov/326 - () http://seclists.org/fulldisclosure/2010/Nov/326 -
References () http://secunia.com/advisories/42347 - () http://secunia.com/advisories/42347 -
References () http://sourceforge.net/projects/pandora/files/Pandora%20FMS%203.1/Final%20version%20%28Stable%29/pandorafms_console-3.1_security_patch_13Oct2010.tar.gz/download - Patch () http://sourceforge.net/projects/pandora/files/Pandora%20FMS%203.1/Final%20version%20%28Stable%29/pandorafms_console-3.1_security_patch_13Oct2010.tar.gz/download - Patch
References () http://www.exploit-db.com/exploits/15643 - Exploit () http://www.exploit-db.com/exploits/15643 - Exploit
References () http://www.securityfocus.com/archive/1/514939/100/0/threaded - () http://www.securityfocus.com/archive/1/514939/100/0/threaded -
References () http://www.securityfocus.com/bid/45112 - Patch () http://www.securityfocus.com/bid/45112 - Patch

Information

Published : 2010-12-02 17:15

Updated : 2024-11-21 01:20


NVD link : CVE-2010-4282

Mitre link : CVE-2010-4282

CVE.ORG link : CVE-2010-4282


JSON object : View

Products Affected

artica

  • pandora_fms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')