PoC Index

CVE-2010-4279

HIGH 10.0EPSS 65.6%

The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.

CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
65.62% chance of exploitation in the next 30 days, 99th percentile
Published
2010-12-02
Updated
2024-08-07

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (2)

References

Related