CVE-2019-20224: OS Command Injection
netflowgetstats in functionsnetflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ipsrc parameter in an index.php?operation/netflow/nfliveview request. This issue has been fixed in Pandora FMS 7.0 NG 742.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20224?
CVE-2019-20224 is a vulnerability in Pandora FMS 7.0NG that allows remote authenticated users to execute arbitrary OS commands.
How can the vulnerability be exploited?
The vulnerability can be exploited by using shell metacharacters in the ip_src parameter in a request to index.php?operation/netflow/nf_live_view.
What is the severity of CVE-2019-20224?
The severity of CVE-2019-20224 is critical, with a severity value of 8.8.
What software versions are affected by CVE-2019-20224?
Pandora FMS 7.0NG is affected by CVE-2019-20224.
How can I fix CVE-2019-20224?
The issue has been fixed in Pandora FMS 7.0 NG 742, so updating to this version will fix the vulnerability.