.. / CVE-2019-20224

Exploit for Pandora FMS 7.0NG - Remote Command Injection (CVE-2019-20224)

Description:

Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request.

Proof of Concept

PoC exploit

Nuclei Template

View the template here CVE-2019-20224.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-20224.yaml
Copy

Try the exploit in a lab environment:

Lab Machine Link
Hack The Box Pandora Go to Practice

References:

https://drive.google.com/file/d/1DkWR5MylzeNr20jmHXTaAIJmf3YN-lnO/view
https://shells.systems/pandorafms-v7-0ng-authenticated-remote-code-execution-cve-2019-20224/
https://nvd.nist.gov/vuln/detail/CVE-2019-20224
https://gist.github.com/mhaskar/2153d66a0928492d76b799ba13b9e3f9
https://pandorafms.com/downloads/solved-pandorafms-742.mp4