Vulnerabilities
Vulnerable Software
Theforeman:  >> Foreman  >> 1.4.1  Security Vulnerabilities
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.
CVSS Score
6.4
EPSS Score
0.024
Published
2014-06-20
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
CVSS Score
7.5
EPSS Score
0.09
Published
2014-06-20
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
CVSS Score
5.0
EPSS Score
0.015
Published
2014-05-08
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
CVSS Score
6.8
EPSS Score
0.014
Published
2014-05-08
Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.
CVSS Score
4.3
EPSS Score
0.019
Published
2014-03-27


Contact Us

Shodan ® - All rights reserved