Fogproject

Fogproject

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.32%
  • Veröffentlicht 21.07.2026 20:42:19
  • Zuletzt bearbeitet 07.08.2026 13:53:14

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data values into HTML table cell templates using `str_re...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 21.07.2026 20:40:31
  • Zuletzt bearbeitet 07.08.2026 13:52:34

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single H...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 21.07.2026 20:39:01
  • Zuletzt bearbeitet 07.08.2026 13:51:46

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<option>` labels using raw, unescaped user input. An unau...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 21.07.2026 20:37:32
  • Zuletzt bearbeitet 07.08.2026 13:50:16

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/inventory.php`) persists client-supplied values without s...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 27.03.2026 19:45:12
  • Zuletzt bearbeitet 08.04.2026 15:08:44

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing tables on multiple management pages (Host, Storage, Group, Image, Printer, Snapin) are vulnerable to Stored Cross-Site Scripting (XS...

  • EPSS 0.38%
  • Veröffentlicht 23.01.2026 00:19:33
  • Zuletzt bearbeitet 15.04.2026 00:35:42

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1754 and below contain an unauthenticated SSRF vulnerability in getversion.php which can be triggered by providing a user-controlled url parameter. It...

Exploit
  • EPSS 18.69%
  • Veröffentlicht 06.09.2025 20:04:25
  • Zuletzt bearbeitet 29.09.2025 13:49:57

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could p...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 02.08.2024 20:17:03
  • Zuletzt bearbeitet 10.09.2024 16:44:12

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via logs stored directly on the root of the web server. FOG Server creates 2 logs on the root of the web ser...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 02.08.2024 20:17:02
  • Zuletzt bearbeitet 10.09.2024 16:49:09

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 31.07.2024 20:15:06
  • Zuletzt bearbeitet 05.09.2024 16:18:09

FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by all users on the host. By exploiting these creden...