CVE-2012-5648
04.04.2014, 14:55
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
Vendor | Product | Version |
---|---|---|
theforeman | foreman | 𝑥 ≤ 1.0 |
theforeman | foreman | 0.1 |
theforeman | foreman | 0.2 |
theforeman | foreman | 0.3 |
theforeman | foreman | 0.4 |
theforeman | foreman | 0.4.1 |
𝑥
= Vulnerable software versions
References