Логотип exploitDog
bind:CVE-2010-2235
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2010-2235

Количество 4

Количество 4

redhat логотип

CVE-2010-2235

больше 15 лет назад

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.

CVSS2: 7.1
EPSS: Низкий
nvd логотип

CVE-2010-2235

около 15 лет назад

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.

CVSS2: 8.5
EPSS: Низкий
debian логотип

CVE-2010-2235

около 15 лет назад

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Sa ...

CVSS2: 8.5
EPSS: Низкий
github логотип

GHSA-jhm7-38xj-pvm8

больше 3 лет назад

Cobbler is vulnerable to code injection

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2010-2235

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.

CVSS2: 7.1
2%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-2235

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.

CVSS2: 8.5
2%
Низкий
около 15 лет назад
debian логотип
CVE-2010-2235

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Sa ...

CVSS2: 8.5
2%
Низкий
около 15 лет назад
github логотип
GHSA-jhm7-38xj-pvm8

Cobbler is vulnerable to code injection

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу