CVE-2018-11221: Malicious File Upload
Published Jun 15, 2018
·Updated
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/updatemanager.ajax in the update system.
Affected Software
1 affected component
Artica Pandora FMS<=7.23
Event History
Jun 15, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-11221.
2
What is the severity of CVE-2018-11221?
The severity of CVE-2018-11221 is critical with a severity value of 9.8.
3
What is the affected software for CVE-2018-11221?
The affected software for CVE-2018-11221 is Artica Pandora FMS version 7.23.
4
How does CVE-2018-11221 work?
CVE-2018-11221 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.
5
Are there any references for CVE-2018-11221?
Yes, you can find references for CVE-2018-11221 at the following links: [Link 1](https://blog.hackercat.ninja/post/pandoras_box/) and [Link 2](https://pandorafms.com/wp-content/uploads/2018/06/whats-new-723-EN.pdf).