References https://nvd.nist.gov/vuln/detail/CVE-2024-39914 https://github.com/FOGProject/fogproject/security/advisories/GHSA-7h44-6vq6-cq8j https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-39914.yaml https://www.offsec.com/blog/cve-2024-39914/ https://medium.com/@dj4msec/cve-2024-39914-bd6696e62782 https://pentest-tools.com/vulnerabilities-exploits/fog-project-151034-remote-command-execution_22980 https://www.sentinelone.com/vulnerability-database/cve-2024-39914/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39914 https://blog.csdn.net/qq_39894062/article/details/140550009 https://rivers.chaitin.cn/blog/cqj67h10lnedo7thpu20 https://blog.csdn.net/weixin_44187657/article/details/141217190
Related VulnerabilitiesFOGProject /fog/management/export.php 信息泄露漏洞(CVE-2025-58443)PoCFOG Project /fog/service/getversion.php 文件读取漏洞(CVE-2026-24138)PoCCVE-2025-58443: FOGProject <= 1.5.10.1673 - Authentication BypassFOG Project FOG 权限管理不当漏洞(CVE-2025-58443) FOG认证绕过漏洞PoCCVE-2022-0747: Infographic Maker iList < 4.3.8 - SQL InjectionPoCCVE-2024-39914: FOG Project < 1.5.10.34 - Remote Command ExecutionFOG Project export.php 文件上传漏洞 (CVE-2024-39914)FOG Project存在命令执行漏洞(CVE-2024-39914)