CVE-2024-41108
- EPSS 0.55%
- Veröffentlicht 31.07.2024 19:15:12
- Zuletzt bearbeitet 05.09.2024 16:27:50
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only the host's mac address is required to obtain the configuration information. This data can only be ret...
CVE-2024-40645
- EPSS 0.96%
- Veröffentlicht 31.07.2024 19:15:11
- Zuletzt bearbeitet 05.09.2024 17:09:16
FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The Rebranding feature has a check on the client banner ima...
CVE-2024-39916
- EPSS 0.29%
- Veröffentlicht 12.07.2024 15:15:11
- Zuletzt bearbeitet 21.11.2024 09:28:33
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer that allows an attacker to modify files outside the export in the defa...
CVE-2024-39914
- EPSS 23.24%
- Veröffentlicht 12.07.2024 15:15:11
- Zuletzt bearbeitet 29.09.2025 13:51:33
FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected by a command injection via the filename parameter to /fog/management/export.php. This vulnerability ...
CVE-2024-34477
- EPSS 0.27%
- Veröffentlicht 27.05.2024 14:15:09
- Zuletzt bearbeitet 26.09.2025 23:59:59
configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In order to exploit the vulnerability, someone needs to mount an NFS share i...
CVE-2023-46237
- EPSS 0.48%
- Veröffentlicht 31.10.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:28:08
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint intended to offer limited enumeration abilities to authenticated users was accessible to unauthenticated users. This enabled unau...
CVE-2023-46236
- EPSS 0.46%
- Veröffentlicht 31.10.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:28:08
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vulnerability allowed an unauthenticated user to trigger a GET request as the server to an arbitrary end...
CVE-2023-46235
- EPSS 0.31%
- Veröffentlicht 31.10.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:28:08
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10.15, due to a lack of request sanitization in the logs, a malicious request containing XSS would be stored in a log file. When an administrator...
CVE-2021-32243
- EPSS 1.12%
- Veröffentlicht 16.06.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:54
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).