packetstormsecurity.com
http://packetstormsecurity.com/files/167503/Pandora-FMS-7.0NG.742-Remote-Code-Execution.html CVE-2020-5844
HIGH
Pandora FMS v7.0NG.742 - Remote Code Execution (RCE) (Authenticated)
Record summary
CVE-2020-5844 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.
Description source: CVE List
Exploitation context
Proofs of concept
3Catalogued exploits
ExploitDBPandora FMS v7.0NG.742 - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby UNICORDNot analyzed1 file
Repository PoCs
GitHubTheCyberGeek/CVE-2020-5844Repository PoCby TheCyberGeekStars: 4Not analyzed2 files
GitHubUNICORDev/exploit-CVE-2020-5844Repository PoCby UNICORDevStars: 7Not analyzed3 files
References
4github.com
https://github.com/TheCyberGeek/CVE-2020-5844 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-5844 pandorafms.com
https://pandorafms.com/