Pandora FMS versions <=7.0NG.722 are vulnerable to unauthenticated remote code execution by chaining an unrestricted file upload (CVE-2018-11221) and a local file inclusion (CVE-2018-11222). An attacker can upload a malicious PHP file as a plugin and execute it via LFI, leading to full compromise of the server.
id: CVE-2018-11222
info:
name: Pandora FMS <=7.0NG.722 - Remote Code Execution
author: iamnoooo
...