The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2009-08-12 10:30
Updated : 2024-02-04 17:33
NVD link : CVE-2008-6954
Mitre link : CVE-2008-6954
CVE.ORG link : CVE-2008-6954
JSON object : View
Products Affected
michael_dehaan
- cobbler
CWE
CWE-264
Permissions, Privileges, and Access Controls