Vulnerability Description
OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artica | Pandora Fms | >= 700, < 777 |
Related Weaknesses (CWE)
References
- https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/Vendor Advisory
- https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/Vendor Advisory
FAQ
What is CVE-2024-35306?
CVE-2024-35306 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.
How severe is CVE-2024-35306?
CVE-2024-35306 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-35306?
Check the references section above for vendor advisories and patch information. Affected products include: Artica Pandora Fms.