CVE-2010-4282
Summary
| CVE | CVE-2010-4282 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-02 17:15:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Artica | Pandora Fms | 1.2 | All | All | All |
| Application | Artica | Pandora Fms | 1.3 | All | All | All |
| Application | Artica | Pandora Fms | 1.3 | beta | All | All |
| Application | Artica | Pandora Fms | 1.3 | beta1 | All | All |
| Application | Artica | Pandora Fms | 1.3 | beta2 | All | All |
| Application | Artica | Pandora Fms | 1.3 | beta3 | All | All |
| Application | Artica | Pandora Fms | 1.3.1 | All | All | All |
| Application | Artica | Pandora Fms | 2.0 | All | All | All |
| Application | Artica | Pandora Fms | 2.0 | beta | All | All |
| Application | Artica | Pandora Fms | 2.1 | All | All | All |
| Application | Artica | Pandora Fms | 2.1.1 | All | All | All |
| Application | Artica | Pandora Fms | 3.0 | All | All | All |
| Application | Artica | Pandora Fms | 3.0 | rc1 | All | All |
| Application | Artica | Pandora Fms | 3.0 | rc2 | All | All |
| Application | Artica | Pandora Fms | 3.1 | rc1 | All | All |
| Application | Artica | Pandora Fms | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: Pandora FMS Authentication Bypass and Multiple Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Pandora FMS <= 3.1 Path Traversal and LFI | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| Pandora FMS Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/69543 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| osvdb.org/69545 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Download Pandora FMS: Flexible Monitoring System from SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| osvdb.org/69544 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Pandora FMS Authentication Bypass And Multiple Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.