CVE-2020-8500: Malicious File Upload
DISPUTED In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8500?
CVE-2020-8500 is a vulnerability in Artica Pandora FMS version 7.42 that allows Web Admin users to execute arbitrary code by uploading a .php file via the Updater or Extension component.
Is CVE-2020-8500 a high severity vulnerability?
Yes, CVE-2020-8500 has a severity level of high with a severity value of 7.2.
How does CVE-2020-8500 affect Artica Pandora FMS?
CVE-2020-8500 affects Artica Pandora FMS version 7.42 and allows Web Admin users to execute arbitrary code by uploading a .php file via the Updater or Extension component.
How can I fix CVE-2020-8500 in Artica Pandora FMS 7.42?
To fix CVE-2020-8500 in Artica Pandora FMS 7.42, it is recommended to apply the latest vendor-provided patches or updates.
Where can I find more information about CVE-2020-8500?
You can find more information about CVE-2020-8500 on the following websites: [https://k4m1ll0.com/cve-2020-8500.html](https://k4m1ll0.com/cve-2020-8500.html), [https://pandorafms.com/downloads/extension-uploader-feature-explained.mp4](https://pandorafms.com/downloads/extension-uploader-feature-explained.mp4)