Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code by using a page parameter containing a UNC share pathname, which bypasses the check for the : (colon) character.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Artica Pandora FMS ajax.php文件代码注入漏洞
Vulnerability Description
Pandora FMS(Flexible Monitoring System)是Pandora FMS团队的一套监控系统。该系统通过可视化的方式监控网络、服务器、虚拟基础架构和应用程序等。 Pandora FMS 3.1.1之前版本中的ajax.php文件中的safe_url_extraclean函数中存在不完整黑名单漏洞。远程攻击者可以通过使用包含UNC共享路径名称的page参数执行任意PHP代码,此漏洞绕过了对":"(冒号)字符的检查。
CVSS Information
N/A
Vulnerability Type
N/A