CVE-2008-6954

The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
michael_dehaancobbler
𝑥
≤ 1.2.8
michael_dehaancobbler
0.1.1.7
michael_dehaancobbler
0.2.1
michael_dehaancobbler
0.2.2
michael_dehaancobbler
0.2.3
michael_dehaancobbler
0.2.5
michael_dehaancobbler
0.2.7
michael_dehaancobbler
0.2.8
michael_dehaancobbler
0.2.9
michael_dehaancobbler
0.3.0
michael_dehaancobbler
0.3.1
michael_dehaancobbler
0.3.3
michael_dehaancobbler
0.3.4
michael_dehaancobbler
0.3.5
michael_dehaancobbler
0.3.6
michael_dehaancobbler
0.3.7
michael_dehaancobbler
0.3.9
michael_dehaancobbler
0.4.0
michael_dehaancobbler
0.4.2
michael_dehaancobbler
0.4.3
michael_dehaancobbler
0.4.5
michael_dehaancobbler
0.4.6
michael_dehaancobbler
0.4.7
michael_dehaancobbler
0.4.8
michael_dehaancobbler
0.5.0
michael_dehaancobbler
0.6.0
michael_dehaancobbler
0.6.1
michael_dehaancobbler
0.6.3
michael_dehaancobbler
0.6.4
michael_dehaancobbler
0.6.5
michael_dehaancobbler
0.8.1
michael_dehaancobbler
0.8.3
michael_dehaancobbler
1.0.0
michael_dehaancobbler
1.0.2
michael_dehaancobbler
1.0.2-1
michael_dehaancobbler
1.0.3-1
michael_dehaancobbler
1.2.0
michael_dehaancobbler
1.2.2
michael_dehaancobbler
1.2.3
michael_dehaancobbler
1.2.5
michael_dehaancobbler
1.2.6
michael_dehaancobbler
1.2.7
𝑥
= Vulnerable software versions
Common Weakness Enumeration