CVE-2010-4278
Pandora FMS < 3.1 - Authenticated OS Command Injection via Network Map Layout Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4278. PoCs published by Juan Galiana Lara.
AI-analyzed exploit summary The writeup describes an OS command injection vulnerability (CVE-2010-4278) in Pandora FMS, where the 'layout' parameter in 'operation/agentes/networkmap.php' is improperly filtered, allowing arbitrary command execution. Proof-of-concept URLs are provided to demonstrate the vulnerability.
Description
operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php.
Exploits (1)
The writeup describes an OS command injection vulnerability (CVE-2010-4278) in Pandora FMS, where the 'layout' parameter in 'operation/agentes/networkmap.php' is improperly filtered, allowing arbitrary command execution. Proof-of-concept URLs are provided to demonstrate the vulnerability.