CVE-2018-11222 Scanner

CVE-2018-11222 Scanner – RCE in Pandora FMS via LFI and File Upload

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

9 days

Scan only one

Domain, Subdomain, IPv4

Toolbox

-

Pandora FMS is an open-source monitoring system for IT infrastructure management. Versions ≤ 7.0NG.722 suffer from a critical Remote Code Execution (RCE) vulnerability that can be exploited without authentication by chaining two separate flaws: unrestricted file upload (CVE-2018-11221) and a local file inclusion vulnerability (CVE-2018-11222).

The attacker can upload a specially crafted ZIP file containing a malicious PHP file via the plugin upload endpoint: /pandora_console/ajax.php?page=include/ajax/update_manager.ajax&upload_file=true. The upload process allows unvalidated file types. The LFI flaw is then used to include and execute the uploaded PHP file via: /pandora_console/ajax.php?page=[path]/plugin/phpinfo.

This results in full server compromise, allowing the attacker to execute arbitrary PHP code with web server privileges. The vulnerability chain has been publicly documented and remains exploitable in unpatched versions.

Impact:

  • Full remote code execution
  • No authentication required
  • Persistent server compromise

REFERENCES

Get started to protecting your digital assets