S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2010-4282 Scanner

CVE-2010-4282 scanner - Directory Traversal vulnerability in Pandora FMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2010-4282
7.5
CVSS

Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Pandora FMS is a popular open-source monitoring system used by businesses and organizations to manage their IT infrastructure and applications. The software enables comprehensive network and system monitoring, comprising real-time data collection, performance management, and event alerts. It features a web-based console that offers a dashboard view of the network to detect issues promptly and improve up-time. 

CVE-2010-4282 is a significant vulnerability found in Pandora FMS before 3.1.1. This vulnerability permits remote attackers to include and execute arbitrary local files by exploiting multiple directory traversal issues. The vulnerabilities are caused by improper handling of user-supplied data when processing input and insufficient sanitization of user inputs.

The exploitation of CVE-2010-4282 could result in dire consequences for naive enterprises. Remote attackers can gain full access to the operating system running Pandora FMS. They can run arbitrary code in the context of the application, steal sensitive data, or use the platform to launch attacks on other systems. The vulnerability could also lead to the complete server takeover, leading to data destruction, exfiltration of sensitive data, and disruption of operations. 

With the s4e.io platform's pro features, businesses and organizations can easily and quickly learn about vulnerabilities in their digital assets. The platform's vulnerability scanner can detect and report security holes in networks, web applications, and operating systems, facilitating risk assessment and mitigation. It provides intelligent cybersecurity measures that cater to businesses of every size, offering affordable, scalable web and mobile application security protection. Companies that utilize this platform are confident in their security posture and can easily defend themselves against threats such as CVE-2010-4282.

 

REFERENCES

Solution Advice

Organizations can protect against CVE-2010-4282 by implementing the following precautions:

  • Keep the Pandora FMS software up to date to ensure all patches and fixes are applied.
  • Block the affected ports on the firewall to limit access to the vulnerable systems.
  • Implement a robust access control mechanism to limit access to the Pandora FMS console.
  • Utilize a web application firewall to block malicious traffic and protect against exploits.
  • All inputs coming to the application must be validated before processing, and special characters stripped.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2010-4282 scanner - Directory Traversal vulnerability in Pandora FMS | S4E