Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
References
Link | Resource |
---|---|
https://medium.com/%40tehwinsam/multiple-xss-on-pandorafms-7-0-ng-744-64b244b8523c | |
https://packetstormsecurity.com/files/158389/Pandora-FMS-7.0-NG-746-Script-Insertion-Code-Execution.htmlPoC | Exploit Third Party Advisory VDB Entry |
https://pandorafms.com/downloads/whats-new-747-EN.pdf | Release Notes Vendor Advisory |
https://www.exploit-db.com/exploits/48707 | Exploit Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-07-13T14:11:58
Updated: 2020-07-30T17:28:38
Reserved: 2020-04-14T00:00:00
Link: CVE-2020-11749
JSON object: View
NVD Information
Status : Modified
Published: 2020-07-13T15:15:14.460
Modified: 2023-11-07T03:15:05.593
Link: CVE-2020-11749
JSON object: View
Redhat Information
No data.
CWE