Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request.
View the template here CVE-2019-20224.yaml
Lab | Machine | Link |
---|---|---|
Hack The Box | Pandora | Go to Practice |
References:
https://drive.google.com/file/d/1DkWR5MylzeNr20jmHXTaAIJmf3YN-lnO/view