First published: Mon Mar 02 2020(Updated: )
** DISPUTED ** In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | =7.42 | |
=7.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8500 is a vulnerability in Artica Pandora FMS version 7.42 that allows Web Admin users to execute arbitrary code by uploading a .php file via the Updater or Extension component.
Yes, CVE-2020-8500 has a severity level of high with a severity value of 7.2.
CVE-2020-8500 affects Artica Pandora FMS version 7.42 and allows Web Admin users to execute arbitrary code by uploading a .php file via the Updater or Extension component.
To fix CVE-2020-8500 in Artica Pandora FMS 7.42, it is recommended to apply the latest vendor-provided patches or updates.
You can find more information about CVE-2020-8500 on the following websites: [https://k4m1ll0.com/cve-2020-8500.html](https://k4m1ll0.com/cve-2020-8500.html), [https://pandorafms.com/downloads/extension-uploader-feature-explained.mp4](https://pandorafms.com/downloads/extension-uploader-feature-explained.mp4)