CVE-2010-4283: Code Injection
Published Dec 2, 2010
·Updated
PHP remote file inclusion vulnerability in extras/pandoradiag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the argv[1] parameter.
Affected Software
16 affected components
Artica Pandora FMS=1.3-beta2
Artica Pandora FMS=1.3-beta
Artica Pandora FMS=1.2
Artica Pandora FMS=2.1.1
Artica Pandora FMS=1.3-beta3
Artica Pandora FMS<=3.1
Artica Pandora FMS=1.3-beta1
Artica Pandora FMS=3.0-rc1
Artica Pandora FMS=2.0
Artica Pandora FMS=1.3
Artica Pandora FMS=2.0-beta
Artica Pandora FMS=3.0-rc2
Artica Pandora FMS=1.3.1
Artica Pandora FMS=2.1
Artica Pandora FMS=3.0
Artica Pandora FMS=3.1-rc1
Remediation
Patch Available
Event History
Dec 2, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4283?
CVE-2010-4283 has a moderate severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2010-4283?
To fix CVE-2010-4283, upgrade to version 3.1.1 or later of Pandora FMS where the vulnerability has been patched.
3
What type of attacks can CVE-2010-4283 facilitate?
CVE-2010-4283 can facilitate remote code execution attacks by exploiting the vulnerable argv[1] parameter.
4
Which versions of Pandora FMS are affected by CVE-2010-4283?
Pandora FMS versions prior to 3.1.1, including 1.3-beta2, 1.3-beta, 1.2, 2.1.1, and others are affected by CVE-2010-4283.
5
Is CVE-2010-4283 easy to exploit?
CVE-2010-4283 is considered relatively easy to exploit since it can be triggered through a specially crafted URL.