|
|||
Rule General Information |
---|
Release Date: | 2024-07-30 | |
Rule Name: | FOGProject export.php Remote Command Execution Vulnerability (CVE-2024-39914) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability is fixed in 1.5.10.34. | |
Impact: | An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Linux, Others | |
Reference: | https://github.com/FOGProject/fogproject/commit/2413bc034753c32799785e9bf08164ccd0a2759f https://github.com/FOGProject/fogproject/security/advisories/GHSA-7h44-6vq6-cq8j |
|
Solutions |
---|
Refer to the announcement or patch by the vendor:https://github.com/FOGProject/fogproject/security/advisories/GHSA-7h44-6vq6-cq8j |