Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2014-0090

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
0
Attacker Value
Unknown

CVE-2013-2121

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
0
Attacker Value
Unknown

CVE-2013-2113

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.
0