Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.805709
Category:Web application abuses
Title:Pandora FMS 5.1 SP1 SNMP Editor XSS Vulnerability
Summary:Pandora FMS is prone to a cross-site scripting (XSS); vulnerability.
Description:Summary:
Pandora FMS is prone to a cross-site scripting (XSS)
vulnerability.

Vulnerability Insight:
Flaw is due to the SNMP trap editor does not validate input to
the 'oid' and 'custom_oid' parameters before returning it to users.

Vulnerability Impact:
Successful exploitation will allow remote attackers to execute
arbitrary HTML and script code in a user's browser session within the trust relationship between
their browser and the server.

Affected Software/OS:
Pandora FMS version 5.1 SP1.

Solution:
As a workaround provide secure restriction or filtering of the
OID and customer OID input fields. Encode and parse the input field context to prevent persistent
execution of script code through the vulnerable snmp editor module.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

CopyrightCopyright (C) 2015 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.