First published: Thu Dec 02 2010(Updated: )
Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_group parameter in an operation/agentes/ver_agente action to ajax.php or (2) the group_id parameter in an operation/agentes/estado_agente action to index.php, related to operation/agentes/estado_agente.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | =1.3-beta2 | |
Artica Pandora FMS | =1.3-beta | |
Artica Pandora FMS | =1.2 | |
Artica Pandora FMS | =2.1.1 | |
Artica Pandora FMS | =1.3-beta3 | |
Artica Pandora FMS | <=3.1 | |
Artica Pandora FMS | =1.3-beta1 | |
Artica Pandora FMS | =3.0-rc1 | |
Artica Pandora FMS | =2.0 | |
Artica Pandora FMS | =1.3 | |
Artica Pandora FMS | =2.0-beta | |
Artica Pandora FMS | =3.0-rc2 | |
Artica Pandora FMS | =1.3.1 | |
Artica Pandora FMS | =2.1 | |
Artica Pandora FMS | =3.0 | |
Artica Pandora FMS | =3.1-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4280 is classified as a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2010-4280, update Pandora FMS to version 3.1.1 or later.
CVE-2010-4280 affects various versions of Pandora FMS prior to 3.1.1, including 1.2, 1.3 beta versions, and 2.x series.
Yes, CVE-2010-4280 can be exploited remotely by authenticated users to execute arbitrary SQL commands.
The attack vectors for CVE-2010-4280 include the id_group parameter in ajax.php and the group_id parameter in ind.php.