Record summary

CVE-2023-44088 has a selected CVSS score of 5.9 (medium); EIP currently links 1 catalogued exploit.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 3, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List700 to ≤ 774affected

Proofs of concept

1

Catalogued exploits

ExploitDBPandoraFMS 7.0NG.772 - SQL InjectionExploitDB exploitby Osama YousefNot analyzed1 file
ExploitDB

PoC details

References

2