SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Pandora FMS Remote Code Execution

Category: WEB-ATTACKS      

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net tools php functionality allows authenticated users to execute arbitrary OS commands via the select ips parameter when performing network tools operations, such as pinging. This occurs because user input is not properly sanitized before being passed to system commands, enabling command injection.


Relevant Information