netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
References
Configurations
History
No history.
Information
Published : 2020-01-09 16:15
Updated : 2024-11-21 04:38
NVD link : CVE-2019-20224
Mitre link : CVE-2019-20224
CVE.ORG link : CVE-2019-20224
JSON object : View
Products Affected
artica
- pandora_fms
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')