CVE-2024-39914
CRITICAL EXPLOITED NUCLEIfogproject < 1.5.10.34 - Command Injection via Filename Parameter
Title source: llmExploitation Summary
CVE-2024-39914 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including 9874621368. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-39914, a command injection vulnerability in FOG Project. The exploit uses DNS exfiltration via dnslog.cn to confirm remote code execution by injecting a curl command into the 'filename' parameter of the export.php endpoint.
Description
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.
Exploits (1)
This repository contains a functional exploit for CVE-2024-39914, a command injection vulnerability in FOG Project. The exploit uses DNS exfiltration via dnslog.cn to confirm remote code execution by injecting a curl command into the 'filename' parameter of the export.php endpoint.
Nuclei Templates (1)
icon_hash="-1952619005"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H