CVE-2010-4281 describes an incomplete blacklist vulnerability in Pandora FMS versions prior to 3.1.1, specifically within the safe_url_extraclean function in ajax.php. This flaw allows remote attackers to execute arbitrary PHP code by supplying a UNC share pathname in the 'page' parameter, bypassing existing colon character checks. With a CVSS score of 7.5, this high-severity vulnerability is easily exploitable over the network with low complexity and no authentication, potentially leading to full compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog and showing no active exploitation or significant community discussion, public exploit code for directory traversal/local file inclusion related to Pandora FMS 3.1 exists on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1CPE matchmatch criteria | cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:artica:pandora_fms:1.2:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:artica:pandora_fms:1.3:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:artica:pandora_fms:1.3:beta:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:artica:pandora_fms:1.3:beta1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.