Page 2 of 12 results (0.024 seconds)

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

11 Mar 2014 — The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remote attackers to execute arbitrary methods via unspecified vectors. El método x_button en el controlador de servicio (vmdb/app/controllers/service_controller.rb) en Red Hat CloudForms 3.0 Management Engine 5.2 permite a atacantes remotos ejecutar métodos arbitrarios a través de vectores no especificados. Red Hat CloudForms Management Engine delivers the insight,... • http://rhn.redhat.com/errata/RHSA-2014-0215.html • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') •

CVSS: 8.8EPSS: 0%CPEs: 3EXPL: 0

14 Jan 2014 — CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request. CloudForms 3.0 Management Engine anterior a la versión 5.2.1.6 permite a atacantes remotos evadir el mecanismo protect_from_forgery de Ruby on Rails y llevar a cabo ataques de CSRF a través de una acción destructiva en una petición. Red Hat CloudForms Management Engine delivers the insig... • http://rhn.redhat.com/errata/RHSA-2014-0025.html • CWE-352: Cross-Site Request Forgery (CSRF) •