CVE-2010-4282: Path Traversal
Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandorahelp.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4282?
CVE-2010-4282 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2010-4282?
To fix CVE-2010-4282, update Pandora FMS to version 3.1.1 or later where the vulnerabilities have been patched.
What types of attacks are possible with CVE-2010-4282?
CVE-2010-4282 allows attackers to perform directory traversal attacks leading to the inclusion and execution of arbitrary local files.
What versions of Pandora FMS are affected by CVE-2010-4282?
CVE-2010-4282 affects multiple versions of Pandora FMS before 3.1.1, including various beta and release candidates.
Can CVE-2010-4282 be exploited remotely?
Yes, CVE-2010-4282 can be exploited remotely without authentication, allowing attackers to execute arbitrary code.