Record summary

CVE-2020-5844 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs.

Description

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2

Proofs of concept

3

Catalogued exploits

ExploitDBPandora FMS v7.0NG.742 - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby UNICORDNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubTheCyberGeek/CVE-2020-5844Repository PoCby TheCyberGeekStars: 4Not analyzed2 files

2.5 KiB

GitHub

PoC details
GitHubUNICORDev/exploit-CVE-2020-5844Repository PoCby UNICORDevStars: 7Not analyzed3 files

17.6 KiB

GitHub

PoC details

References

4