Описание
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
Ссылки
- Patch
- Patch
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:redhat:openstack:3.0:*:*:*:*:*:*:*
Конфигурация 2Версия до 1.2.2 (включая)
Одно из
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.2.1:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00354
Низкий
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
redhat
почти 12 лет назад
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
debian
больше 11 лет назад
Multiple SQL injection vulnerabilities in app/models/concerns/host_com ...
github
больше 3 лет назад
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
EPSS
Процентиль: 57%
0.00354
Низкий
7.5 High
CVSS2
Дефекты
CWE-89