RULE(RULE ID:335312)

Rule General Information
Release Date: 2021-12-20
Rule Name: Pandora FMS Arbitrary Command Injection Vulnerability (CVE-2019-20224)
Severity:
CVE ID:
Rule Protection Details
Description: netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/155897/Pandora-7.0NG-Remote-Code-Execution.html
https://drive.google.com/file/d/1DkWR5MylzeNr20jmHXTaAIJmf3YN-lnO/view?usp=sharing
https://gist.github.com/mhaskar/2153d66a0928492d76b799ba13b9e3f9
https://pandorafms.com/downloads/solved-pandorafms-742.mp4
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
http://pandorafms.org/