CVE-2024-39914
FOG has a command injection in /fog/management/export.php?filename=
Record summary
CVE-2024-39914 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
fogprojectBrowse FOGProject / fogprojectDefault status: unknown | CVE List | < 1.5.10.34 | affected |
| Before 1.5.10.34 | affected | ||
Proofs of concept
1Repository PoCs
GitHub9874621368/FOG-ProjectRepository PoCby 9874621368Stars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALFOG Project < 1.5.10.34 - Remote Command ExecutionCVSS 9.8
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php.
Impact
Unauthenticated attackers can exploit command injection to achieve remote code execution on the FOG server.
Remediation
Update FOG Project to version 1.5.10.34 or later.
Source: ProjectDiscovery