The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T03:43:13.319Z
Reserved: 2010-11-17T00:00:00
Link: CVE-2010-4279
No data.
Status : Deferred
Published: 2010-12-02T17:15:00.503
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-4279
No data.
OpenCVE Enrichment
No data.
Weaknesses