7.5

CVE-2012-2395

Exploit
Incomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Michael DehaanCobbler Version2.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.56% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00016.html
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00000.html
http://www.openwall.com/lists/oss-security/2012/05/23/18
http://www.openwall.com/lists/oss-security/2012/05/23/4
http://www.osvdb.org/82458
http://www.securityfocus.com/bid/53666
https://bugs.launchpad.net/ubuntu/+source/cobbler/+bug/978999
https://github.com/cobbler/cobbler/commit/6d9167e5da44eca56bdf42b5776097a6779aaadf
Patch
Exploit
https://github.com/cobbler/cobbler/issues/141