Exploitation Summary
EIP tracks 3 public exploits for CVE-2020-5844. PoCs published by UNICORD, UNICORDev, TheCyberGeek.
AI-analyzed exploit summary This exploit targets CVE-2020-5844 in Pandora FMS v7.0NG.742, allowing authenticated administrators to upload a malicious PHP script via a file upload vulnerability. The script can execute arbitrary commands, including reverse shells, through a base64-decoded payload.
Description
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.
Exploits (3)
This exploit targets CVE-2020-5844 in Pandora FMS v7.0NG.742, allowing authenticated administrators to upload a malicious PHP script via a file upload vulnerability. The script can execute arbitrary commands, including reverse shells, through a base64-decoded payload.
This repository contains a functional Python exploit for CVE-2020-5844, targeting Pandora FMS v7.0NG.742. The exploit allows authenticated administrators to upload and execute malicious PHP scripts via a file upload vulnerability in the extensions/files_repo endpoint.
This repository contains a functional Python exploit for CVE-2020-5844, an authenticated RCE vulnerability in PandoraFMS 7.0-NG 742. The exploit uploads a malicious PHP file via the file repository feature and triggers execution by accessing the uploaded file.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H