CVE report
CVE-2024-44349critical
AnteeoWMS < v4.7.34 - SQL Injection
Events 90d
44
Distinct IPs
5
Severity
critical
CISA KEV
Not listed
Detection signature
An event counts toward CVE-2024-44349 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- · /default.aspx
Pre-disclosure activity
all early actors →Analysing probe history around the publication date…
Recent probe volume (last 7 days)
peak: 15 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2024-44349
Top networks the attempts come from
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
ja4h: ge11nn0400_c3abebcf3d28ja4h: ge11nn0500_2223cffcb26cja4h: ge11nn0300_0db47b7d240dja4h: ge11nn06en_e4773a62bf4cja4h: ge11nn0500_9af7e0472034ja4h: ge11nn0400_ef4d07580f66ja4: t13i100800_61a7ad8aa9b6_d268365384ffja4: t13i131300_f57a46bbacb6_3b244d8fbcc8ja4: t13i251000_b78ed14e2fd0_ab7e3b40a677ja4: t13i1811h1_85036bcba153_d41ae481755eja4: t13i131000_f57a46bbacb6_ab7e3b40a677
Sample request paths observed
- /RDWeb/Pages/en-US/Default.aspx
- /_windows/default.aspx
- /_windows/default.aspx/
- /RDWeb/Pages/tr-TR/Default.aspx
- /website/Default.aspx
- /default.aspx
- /default.aspx/
- /Admin/Access/Setup/Default.aspx?Action=createadministrator&adminusername=17045ljshm&adminpassword=17894feixr&adminemail=14543gaukn@test.com&adminname=test
- /Admin/Access/Setup/Default.aspx?Action=createadministrator&adminusername=UzvfbE&adminpassword=8LEHwi&adminemail=test@test.com&adminname=test