CVE Browser
FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group Inventory tab
FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of host encryption keys and power schedules
FOGProject has stored XSS via unescaped option label in selectForm() accessible from unauthenticated inventory endpoint
FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host Management page
FOG has Stored XSS in Multiple Management Pages
FOG vulnerable to unauthenticated SSRF via `/fog/service/getversion.php`
FOG's authentication bypass leads to full SQL DB dump
FOG has a Log Information Disclosure
FOG leaks sensitive information (AD domain, username and password)
FOG Weak file permissions
FOG Sensitive Information Disclosure
FOG Authenticated File Upload RCE
NFS server misconfiguration allows file access outside the exported directory
FOG has a command injection in /fog/management/export.php?filename=
configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash…
FOG path traversal via unauthenticated endpoint
FOG SSRF via unauthenticated endpoint(s)
FOG stored XSS on log screen via unsanitized request logging
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).
Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27 through 0.32 allow remote authenticated users to inject arbitrary web script or HTML via the (1…
Showing 1 to 20 CVEs · page 1