CVE-2020-5844

HIGH

Pandora FMS v7.0 NG - Authenticated RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2020-5844. PoCs published by UNICORD, UNICORDev, TheCyberGeek.

AI-analyzed exploit summary This exploit targets CVE-2020-5844 in Pandora FMS v7.0NG.742, allowing authenticated administrators to upload a malicious PHP script via a file upload vulnerability. The script can execute arbitrary commands, including reverse shells, through a base64-decoded payload.

Description

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.

Exploits (3)

exploitdb WORKING POC
by UNICORD · pythonwebappsphp
https://www.exploit-db.com/exploits/50961

This exploit targets CVE-2020-5844 in Pandora FMS v7.0NG.742, allowing authenticated administrators to upload a malicious PHP script via a file upload vulnerability. The script can execute arbitrary commands, including reverse shells, through a base64-decoded payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Pandora FMS v7.0NG.742
Auth required
Prerequisites: Valid credentials or PHPSESSID for authenticated access · Network access to the target Pandora FMS instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 7 stars
by UNICORDev · poc
https://github.com/UNICORDev/exploit-CVE-2020-5844

This repository contains a functional Python exploit for CVE-2020-5844, targeting Pandora FMS v7.0NG.742. The exploit allows authenticated administrators to upload and execute malicious PHP scripts via a file upload vulnerability in the extensions/files_repo endpoint.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Pandora FMS v7.0NG.742
Auth required
Prerequisites: Valid credentials or PHPSESSID for authentication · Network access to the target Pandora FMS instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 6 stars
by TheCyberGeek · poc
https://github.com/TheCyberGeek/CVE-2020-5844

This repository contains a functional Python exploit for CVE-2020-5844, an authenticated RCE vulnerability in PandoraFMS 7.0-NG 742. The exploit uploads a malicious PHP file via the file repository feature and triggers execution by accessing the uploaded file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: PandoraFMS 7.0-NG 742
Auth required
Prerequisites: Valid admin credentials for PandoraFMS · Access to the target's web interface · A PHP reverse shell file
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Product x_refsource_misc
https://pandorafms.com
Exploit, Third Party Advisory x_refsource_misc
https://github.com/TheCyberGeek/CVE-2020-5844

Scores

CVSS v3 7.2
EPSS 0.7310
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
artica/pandora_fms 7.0_ng
Published Mar 16, 2020
Tracked Since Feb 18, 2026