.. / CVE-2010-4282

Exploit for phpShowtime 2.0 - Directory Traversal (CVE-2010-4282)

Description:

Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.

Nuclei Template

View the template here CVE-2010-4282.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2010/CVE-2010-4282.yaml
Copy

References:

http://sourceforge.net/projects/pandora/files/Pandora%20FMS%203.1/Final%20version%20%28Stable%29/pandorafms_console-3.1_security_patch_13Oct2010.tar.gz/download
https://nvd.nist.gov/vuln/detail/CVE-2010-4282
http://seclists.org/fulldisclosure/2010/Nov/326
http://www.exploit-db.com/exploits/15643
https://www.exploit-db.com/exploits/15643