Vulnerabilities
Vulnerable Software
Theforeman:  >> Foreman  >> 1.2.2  Security Vulnerabilities
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.
CVSS Score
6.4
EPSS Score
0.024
Published
2014-06-20
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
CVSS Score
7.5
EPSS Score
0.09
Published
2014-06-20
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
CVSS Score
6.8
EPSS Score
0.014
Published
2014-05-08
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
CVSS Score
7.5
EPSS Score
0.012
Published
2013-11-20


Contact Us

Shodan ® - All rights reserved