CVE-2010-4280: SQL Injection
Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the idgroup parameter in an operation/agentes/veragente action to ajax.php or (2) the groupid parameter in an operation/agentes/estadoagente action to index.php, related to operation/agentes/estadoagente.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4280?
CVE-2010-4280 is classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2010-4280?
To fix CVE-2010-4280, update Pandora FMS to version 3.1.1 or later.
What systems are affected by CVE-2010-4280?
CVE-2010-4280 affects various versions of Pandora FMS prior to 3.1.1, including 1.2, 1.3 beta versions, and 2.x series.
Can CVE-2010-4280 be exploited remotely?
Yes, CVE-2010-4280 can be exploited remotely by authenticated users to execute arbitrary SQL commands.
What are the attack vectors for CVE-2010-4280?
The attack vectors for CVE-2010-4280 include the id_group parameter in ajax.php and the group_id parameter in ind.php.