Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv9r-c8f3-vqh2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request.

netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request.

EPSS

Процентиль: 100%
0.93568
Критический

Связанные уязвимости

CVSS3: 8.8
nvd
около 6 лет назад

netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.

EPSS

Процентиль: 100%
0.93568
Критический