Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2015-5152
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2014-3491
Disclosure Date: July 01, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification boxes.
0
Attacker Value
Unknown
CVE-2014-3492
Disclosure Date: July 01, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote attackers to inject arbitrary web script or HTML via a parameter (1) name or (2) value related to the host.
0
Attacker Value
Unknown
CVE-2014-4507
Disclosure Date: June 20, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.
0
Attacker Value
Unknown
CVE-2014-0007
Disclosure Date: June 20, 2014 (last updated October 05, 2023)
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
0
Attacker Value
Unknown
CVE-2014-0192
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
0
Attacker Value
Unknown
CVE-2014-0090
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
0
Attacker Value
Unknown
CVE-2014-0089
Disclosure Date: March 27, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.
0