Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-23749

KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). This allows an attacker to add inputs inside the filename variable, leading to arbitrary code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.0%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2024-23749
  • 9bis » Kitty » Version: 0.66.6.3
    cpe:2.3:a:9bis:kitty:0.66.6.3
  • 9bis » Kitty » Version: 0.70.0.9
    cpe:2.3:a:9bis:kitty:0.70.0.9
  • 9bis » Kitty » Version: 0.71.0.1
    cpe:2.3:a:9bis:kitty:0.71.0.1
  • 9bis » Kitty » Version: 0.71.0.2
    cpe:2.3:a:9bis:kitty:0.71.0.2
  • 9bis » Kitty » Version: 0.71.0.3
    cpe:2.3:a:9bis:kitty:0.71.0.3
  • 9bis » Kitty » Version: 0.71.0.4
    cpe:2.3:a:9bis:kitty:0.71.0.4
  • 9bis » Kitty » Version: 0.71.0.5
    cpe:2.3:a:9bis:kitty:0.71.0.5
  • 9bis » Kitty » Version: 0.71.0.6
    cpe:2.3:a:9bis:kitty:0.71.0.6
  • 9bis » Kitty » Version: 0.71.0.7
    cpe:2.3:a:9bis:kitty:0.71.0.7
  • 9bis » Kitty » Version: 0.72.0.1
    cpe:2.3:a:9bis:kitty:0.72.0.1
  • 9bis » Kitty » Version: 0.72.0.2
    cpe:2.3:a:9bis:kitty:0.72.0.2
  • 9bis » Kitty » Version: 0.72.0.3
    cpe:2.3:a:9bis:kitty:0.72.0.3
  • 9bis » Kitty » Version: 0.72.0.4
    cpe:2.3:a:9bis:kitty:0.72.0.4
  • 9bis » Kitty » Version: 0.72.0.5
    cpe:2.3:a:9bis:kitty:0.72.0.5
  • 9bis » Kitty » Version: 0.72.0.6
    cpe:2.3:a:9bis:kitty:0.72.0.6
  • 9bis » Kitty » Version: 0.73.0.1
    cpe:2.3:a:9bis:kitty:0.73.0.1
  • 9bis » Kitty » Version: 0.73.0.2
    cpe:2.3:a:9bis:kitty:0.73.0.2
  • 9bis » Kitty » Version: 0.73.1.1
    cpe:2.3:a:9bis:kitty:0.73.1.1
  • 9bis » Kitty » Version: 0.73.1.2
    cpe:2.3:a:9bis:kitty:0.73.1.2
  • 9bis » Kitty » Version: 0.73.1.3
    cpe:2.3:a:9bis:kitty:0.73.1.3
  • 9bis » Kitty » Version: 0.73.1.4
    cpe:2.3:a:9bis:kitty:0.73.1.4
  • 9bis » Kitty » Version: 0.73.1.5
    cpe:2.3:a:9bis:kitty:0.73.1.5
  • 9bis » Kitty » Version: 0.73.2.1
    cpe:2.3:a:9bis:kitty:0.73.2.1
  • 9bis » Kitty » Version: 0.73.2.10
    cpe:2.3:a:9bis:kitty:0.73.2.10
  • 9bis » Kitty » Version: 0.73.2.11
    cpe:2.3:a:9bis:kitty:0.73.2.11
  • 9bis » Kitty » Version: 0.73.2.12
    cpe:2.3:a:9bis:kitty:0.73.2.12
  • 9bis » Kitty » Version: 0.73.2.13
    cpe:2.3:a:9bis:kitty:0.73.2.13
  • 9bis » Kitty » Version: 0.73.2.14
    cpe:2.3:a:9bis:kitty:0.73.2.14
  • 9bis » Kitty » Version: 0.73.2.15
    cpe:2.3:a:9bis:kitty:0.73.2.15
  • 9bis » Kitty » Version: 0.73.2.16
    cpe:2.3:a:9bis:kitty:0.73.2.16
  • 9bis » Kitty » Version: 0.73.2.17
    cpe:2.3:a:9bis:kitty:0.73.2.17
  • 9bis » Kitty » Version: 0.73.2.18
    cpe:2.3:a:9bis:kitty:0.73.2.18
  • 9bis » Kitty » Version: 0.73.2.2
    cpe:2.3:a:9bis:kitty:0.73.2.2
  • 9bis » Kitty » Version: 0.73.2.3
    cpe:2.3:a:9bis:kitty:0.73.2.3
  • 9bis » Kitty » Version: 0.73.2.4
    cpe:2.3:a:9bis:kitty:0.73.2.4
  • 9bis » Kitty » Version: 0.73.2.5
    cpe:2.3:a:9bis:kitty:0.73.2.5
  • 9bis » Kitty » Version: 0.73.2.6
    cpe:2.3:a:9bis:kitty:0.73.2.6
  • 9bis » Kitty » Version: 0.73.2.7
    cpe:2.3:a:9bis:kitty:0.73.2.7
  • 9bis » Kitty » Version: 0.73.2.8
    cpe:2.3:a:9bis:kitty:0.73.2.8
  • 9bis » Kitty » Version: 0.73.2.9
    cpe:2.3:a:9bis:kitty:0.73.2.9
  • 9bis » Kitty » Version: 0.74.0.1
    cpe:2.3:a:9bis:kitty:0.74.0.1
  • 9bis » Kitty » Version: 0.74.0.2
    cpe:2.3:a:9bis:kitty:0.74.0.2
  • 9bis » Kitty » Version: 0.74.0.3
    cpe:2.3:a:9bis:kitty:0.74.0.3
  • 9bis » Kitty » Version: 0.74.0.4
    cpe:2.3:a:9bis:kitty:0.74.0.4
  • 9bis » Kitty » Version: 0.74.0.5
    cpe:2.3:a:9bis:kitty:0.74.0.5
  • 9bis » Kitty » Version: 0.74.0.6
    cpe:2.3:a:9bis:kitty:0.74.0.6
  • 9bis » Kitty » Version: 0.74.0.7
    cpe:2.3:a:9bis:kitty:0.74.0.7
  • 9bis » Kitty » Version: 0.74.1.1
    cpe:2.3:a:9bis:kitty:0.74.1.1
  • 9bis » Kitty » Version: 0.74.2.1
    cpe:2.3:a:9bis:kitty:0.74.2.1
  • 9bis » Kitty » Version: 0.74.2.2
    cpe:2.3:a:9bis:kitty:0.74.2.2
  • 9bis » Kitty » Version: 0.74.2.3
    cpe:2.3:a:9bis:kitty:0.74.2.3
  • 9bis » Kitty » Version: 0.74.2.4
    cpe:2.3:a:9bis:kitty:0.74.2.4
  • 9bis » Kitty » Version: 0.74.2.5
    cpe:2.3:a:9bis:kitty:0.74.2.5
  • 9bis » Kitty » Version: 0.74.2.6
    cpe:2.3:a:9bis:kitty:0.74.2.6
  • 9bis » Kitty » Version: 0.74.2.7
    cpe:2.3:a:9bis:kitty:0.74.2.7
  • 9bis » Kitty » Version: 0.74.2.8
    cpe:2.3:a:9bis:kitty:0.74.2.8
  • 9bis » Kitty » Version: 0.74.3.1
    cpe:2.3:a:9bis:kitty:0.74.3.1
  • 9bis » Kitty » Version: 0.74.3.2
    cpe:2.3:a:9bis:kitty:0.74.3.2
  • 9bis » Kitty » Version: 0.74.3.3
    cpe:2.3:a:9bis:kitty:0.74.3.3
  • 9bis » Kitty » Version: 0.74.3.4
    cpe:2.3:a:9bis:kitty:0.74.3.4
  • 9bis » Kitty » Version: 0.74.3.5
    cpe:2.3:a:9bis:kitty:0.74.3.5
  • 9bis » Kitty » Version: 0.74.4.1
    cpe:2.3:a:9bis:kitty:0.74.4.1
  • 9bis » Kitty » Version: 0.74.4.10
    cpe:2.3:a:9bis:kitty:0.74.4.10
  • 9bis » Kitty » Version: 0.74.4.11
    cpe:2.3:a:9bis:kitty:0.74.4.11
  • 9bis » Kitty » Version: 0.74.4.12
    cpe:2.3:a:9bis:kitty:0.74.4.12
  • 9bis » Kitty » Version: 0.74.4.13
    cpe:2.3:a:9bis:kitty:0.74.4.13
  • 9bis » Kitty » Version: 0.74.4.2
    cpe:2.3:a:9bis:kitty:0.74.4.2
  • 9bis » Kitty » Version: 0.74.4.3
    cpe:2.3:a:9bis:kitty:0.74.4.3
  • 9bis » Kitty » Version: 0.74.4.4
    cpe:2.3:a:9bis:kitty:0.74.4.4
  • 9bis » Kitty » Version: 0.74.4.5
    cpe:2.3:a:9bis:kitty:0.74.4.5
  • 9bis » Kitty » Version: 0.74.4.6
    cpe:2.3:a:9bis:kitty:0.74.4.6
  • 9bis » Kitty » Version: 0.74.4.7
    cpe:2.3:a:9bis:kitty:0.74.4.7
  • 9bis » Kitty » Version: 0.74.4.8
    cpe:2.3:a:9bis:kitty:0.74.4.8
  • 9bis » Kitty » Version: 0.74.4.9
    cpe:2.3:a:9bis:kitty:0.74.4.9
  • 9bis » Kitty » Version: 0.76.1.13
    cpe:2.3:a:9bis:kitty:0.76.1.13


Contact Us

Shodan ® - All rights reserved