CVE-2019-20050
Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated
Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder with a "tricky" name in the filemanager. The exploit works when the php-fileinfo extension is disabled on the host system.
The attacker must include shell metacharacters in the content type.
MEDIUM · CVSS 6.8
EPSS 0.03835
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0