CVE-2013-4386
20.11.2013, 14:12
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
| Vendor | Product | Version |
|---|---|---|
| redhat | openstack | 3.0 |
| theforeman | foreman | 𝑥 ≤ 1.2.2 |
| theforeman | foreman | 1.2.0 |
| theforeman | foreman | 1.2.0:rc1 |
| theforeman | foreman | 1.2.0:rc2 |
| theforeman | foreman | 1.2.1 |
𝑥
= Vulnerable software versions
References