First published: Thu Dec 02 2010(Updated: )
Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | =1.3-beta2 | |
Artica Pandora FMS | =1.3-beta | |
Artica Pandora FMS | =1.2 | |
Artica Pandora FMS | =2.1.1 | |
Artica Pandora FMS | =1.3-beta3 | |
Artica Pandora FMS | <=3.1 | |
Artica Pandora FMS | =1.3-beta1 | |
Artica Pandora FMS | =3.0-rc1 | |
Artica Pandora FMS | =2.0 | |
Artica Pandora FMS | =1.3 | |
Artica Pandora FMS | =2.0-beta | |
Artica Pandora FMS | =3.0-rc2 | |
Artica Pandora FMS | =1.3.1 | |
Artica Pandora FMS | =2.1 | |
Artica Pandora FMS | =3.0 | |
Artica Pandora FMS | =3.1-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.