First published: Fri Oct 27 2017(Updated: )
Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition. This also implies that general OS information is leaked (e.g., a /var/www pathname typically means Linux or UNIX).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15937 is classified as a medium severity vulnerability due to the potential exposure of sensitive system information.
CVE-2017-15937 can lead to leaking the full installation pathname and revealing general OS information, which may facilitate further attacks.
To fix CVE-2017-15937, update to a version of Artica Pandora FMS that addresses this vulnerability.
CVE-2017-15937 affects Artica Pandora FMS version 7.0 specifically.
CVE-2017-15937 leaks the full installation pathname along with general OS information through GET data.