CVE-2008-6954
12.08.2009, 10:30
The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.Enginsight
Vendor | Product | Version |
---|---|---|
michael_dehaan | cobbler | 𝑥 ≤ 1.2.8 |
michael_dehaan | cobbler | 0.1.1.7 |
michael_dehaan | cobbler | 0.2.1 |
michael_dehaan | cobbler | 0.2.2 |
michael_dehaan | cobbler | 0.2.3 |
michael_dehaan | cobbler | 0.2.5 |
michael_dehaan | cobbler | 0.2.7 |
michael_dehaan | cobbler | 0.2.8 |
michael_dehaan | cobbler | 0.2.9 |
michael_dehaan | cobbler | 0.3.0 |
michael_dehaan | cobbler | 0.3.1 |
michael_dehaan | cobbler | 0.3.3 |
michael_dehaan | cobbler | 0.3.4 |
michael_dehaan | cobbler | 0.3.5 |
michael_dehaan | cobbler | 0.3.6 |
michael_dehaan | cobbler | 0.3.7 |
michael_dehaan | cobbler | 0.3.9 |
michael_dehaan | cobbler | 0.4.0 |
michael_dehaan | cobbler | 0.4.2 |
michael_dehaan | cobbler | 0.4.3 |
michael_dehaan | cobbler | 0.4.5 |
michael_dehaan | cobbler | 0.4.6 |
michael_dehaan | cobbler | 0.4.7 |
michael_dehaan | cobbler | 0.4.8 |
michael_dehaan | cobbler | 0.5.0 |
michael_dehaan | cobbler | 0.6.0 |
michael_dehaan | cobbler | 0.6.1 |
michael_dehaan | cobbler | 0.6.3 |
michael_dehaan | cobbler | 0.6.4 |
michael_dehaan | cobbler | 0.6.5 |
michael_dehaan | cobbler | 0.8.1 |
michael_dehaan | cobbler | 0.8.3 |
michael_dehaan | cobbler | 1.0.0 |
michael_dehaan | cobbler | 1.0.2 |
michael_dehaan | cobbler | 1.0.2-1 |
michael_dehaan | cobbler | 1.0.3-1 |
michael_dehaan | cobbler | 1.2.0 |
michael_dehaan | cobbler | 1.2.2 |
michael_dehaan | cobbler | 1.2.3 |
michael_dehaan | cobbler | 1.2.5 |
michael_dehaan | cobbler | 1.2.6 |
michael_dehaan | cobbler | 1.2.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References