Record summary

CVE-2018-11222 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 26, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHPandora FMS <=7.0NG.722 - Remote Code ExecutionCVSS 7.5

Pandora FMS versions <=7.0NG.722 are vulnerable to unauthenticated remote code execution by chaining an unrestricted file upload (CVE-2018-11221) and a local file inclusion (CVE-2018-11222). An attacker can upload a malicious PHP file as a plugin and execute it via LFI, leading to full compromise of the server.

Impact

Unauthenticated attackers can upload malicious PHP files and execute them via local file inclusion, leading to complete server compromise and access to all managed systems.

Remediation

Upgrade to Pandora FMS version 7.0NG.723 or later.

WeaknessesCWE-20
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2018rcefile-uploadlfipandoraintrusivevkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:*
Shodan: http.html:"pandora fms - installation wizard"
Shodan: http.title:"pandora fms"
FOFA: body="pandora fms - installation wizard"
FOFA: title="pandora fms"
Google: intitle:"pandora fms"

Source: ProjectDiscovery

References

3