CVE-2024-35374

Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.
Configurations

No configuration.

History

21 Nov 2024, 09:20

Type Values Removed Values Added
References () https://chocapikk.com/posts/2024/mocodo-vulnerabilities/ - () https://chocapikk.com/posts/2024/mocodo-vulnerabilities/ -
References () https://github.com/laowantong/mocodo/blob/11ca879060a68e06844058cd969c6379214cc2a8/web/generate.php#L104-L158 - () https://github.com/laowantong/mocodo/blob/11ca879060a68e06844058cd969c6379214cc2a8/web/generate.php#L104-L158 -

20 Aug 2024, 15:35

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

28 May 2024, 17:15

Type Values Removed Values Added
Summary (en) Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary SQL commands and potentially command injection, leading to remote code execution (RCE) under certain conditions. (en) Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

28 May 2024, 12:39

Type Values Removed Values Added
Summary
  • (es) Mocodo Mocodo Online 4.2.6 y versiones anteriores no desinfecta adecuadamente el campo de entrada sql_case en /web/generate.php, lo que permite a atacantes remotos ejecutar comandos SQL arbitrarios y potencialmente inyección de comandos, lo que lleva a la ejecución remota de código (RCE) bajo ciertas condiciones.

24 May 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-24 21:15

Updated : 2024-11-21 09:20


NVD link : CVE-2024-35374

Mitre link : CVE-2024-35374

CVE.ORG link : CVE-2024-35374


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')