AI description
CVE-2024-39914 is a command injection vulnerability affecting FOG, a cloning/imaging/rescue suite/inventory management system. Specifically, versions prior to 1.5.10.34 are vulnerable. The vulnerability exists in the `packages/web/lib/fog/reportmaker.class.php` file, where the `filename` parameter to `/fog/management/export.php` is susceptible to command injection. This vulnerability allows attackers to inject arbitrary system commands by manipulating the `filename` parameter. Successful exploitation could lead to the execution of arbitrary system commands or the deployment of persistent webshells. The vulnerability has been fixed in version 1.5.10.34.
- Description
- FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-77
- Hype score
- Not currently trending
CVE-2024-39914 – #Unauthenticated #Command_Injection in #FOG Project's export.php https://t.co/i6avgbmrPc https://t.co/ljP3amDIKK
@omvapt
27 Jun 2025
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Deep Dive: CVE-2024-39914 (Command Injection in FOG Project's export.php) ⚠️ CVSS 9.8 | EPSS 92.67% Unauthenticated access + unsanitized shell calls = remote command execution. Attackers can inject system commands via the filename parameter, no login required. Just drop a
@offsectraining
26 Jun 2025
7158 Impressions
9 Retweets
71 Likes
16 Bookmarks
2 Replies
0 Quotes
🚨 New PoC Alert: FOGProject FOG Command Injection Vulnerability🚨 📛CVE-2024-39914 🟠 CVSS: 9.8 ⚠️ CWE: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection') 📈 Impact: Code Execution 🛠️ TTPs: T1190 - Exploit Public-Facing Application 🔗…
@gothburz
30 Dec 2024
103 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes