Vulnerabilities (CVE)

Filtered by vendor Artica Subscribe
Filtered by product Pandora Fms
Total 43 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-15936 1 Artica 1 Pandora Fms 2017-11-14 3.5 LOW 5.4 MEDIUM
In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.
CVE-2017-15935 1 Artica 1 Pandora Fms 2017-11-14 9.0 HIGH 7.2 HIGH
Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrators who upload a PHP file.
CVE-2017-15934 1 Artica 1 Pandora Fms 2017-11-14 3.5 LOW 5.4 MEDIUM
Artica Pandora FMS version 7.0 is vulnerable to stored Cross-Site Scripting in the map name parameter.