Vulnerabilities
Vulnerable Software
Theforeman:  >> Foreman  >> 1.4.2  Security Vulnerabilities
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.
CVSS Score
6.4
EPSS Score
0.024
Published
2014-06-20
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
CVSS Score
7.5
EPSS Score
0.09
Published
2014-06-20
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
CVSS Score
5.0
EPSS Score
0.015
Published
2014-05-08


Contact Us

Shodan ® - All rights reserved