Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2015-5152

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
0
Attacker Value
Unknown

CVE-2014-3491

Disclosure Date: July 01, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification boxes.
0
Attacker Value
Unknown

CVE-2014-3492

Disclosure Date: July 01, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote attackers to inject arbitrary web script or HTML via a parameter (1) name or (2) value related to the host.
0
Attacker Value
Unknown

CVE-2014-4507

Disclosure Date: June 20, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.
0
Attacker Value
Unknown

CVE-2014-0007

Disclosure Date: June 20, 2014 (last updated October 05, 2023)
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
0
Attacker Value
Unknown

CVE-2014-0192

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
0
Attacker Value
Unknown

CVE-2014-0090

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
0
Attacker Value
Unknown

CVE-2014-0089

Disclosure Date: March 27, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.
0