CVE-2019-20224
HIGH NUCLEIPandora FMS 7.0NG - Authenticated OS Command Injection via netflow_get_stats ip_src Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-20224. PoCs published by mhaskar. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2019-20224, a post-authentication remote code execution vulnerability in Pandora FMS v7.0NG. The exploit leverages a command injection flaw in the 'ip_src' parameter of the netflow live view feature to execute arbitrary commands via a reverse shell.
Description
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
Exploits (1)
This repository contains a functional Python exploit for CVE-2019-20224, a post-authentication remote code execution vulnerability in Pandora FMS v7.0NG. The exploit leverages a command injection flaw in the 'ip_src' parameter of the netflow live view feature to execute arbitrary commands via a reverse shell.
Nuclei Templates (1)
http.title:"pandora fms"
title="pandora fms"
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H