
CVE-2010-1171 – rhn_satellite: Improper channel comps information management
https://notcve.org/view.php?id=CVE-2010-1171
18 Apr 2011 — Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels. Vulnerabilidad de redirección abierta en el obsoleto API de XML-RPC en Red Hat Network (RHN) Satellite v5.3 y v5.4, que permite a usuarios remotos autenticados acceder a archivos arbitrarios y causar una denegación de ... • http://secunia.com/advisories/44150 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2009-0788 – rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
https://notcve.org/view.php?id=CVE-2009-0788
18 Apr 2011 — Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors. Red Hat Network (RHN) Satellite Server 5.3 y 5.4 no reescribe correctamente URLs no especificadas, lo que permite a atacantes remotos (1) obtener información sensible no especificado del anfitrión o (2) utilizar e... • http://secunia.com/advisories/44150 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •