Page 3 of 13 results (0.002 seconds)

CVSS: 7.2EPSS: 0%CPEs: 80EXPL: 0

Cobbler before 2.0.4 uses an incorrect umask value, which allows local users to have an unspecified impact by leveraging world writable permissions for files and directories. Cobbler en versiones anteriores a la 2.0.4 usa un valor de umask incorrecto, lo que permite a usuarios locales tener un impacto no especificado aprovechando permisos de escritura para todos en ficheros y directorios. • http://people.fedoraproject.org/~shenson/cobbler/cobbler-2.0.8.tar.gz http://secunia.com/advisories/42602 https://bugzilla.redhat.com/show_bug.cgi?id=554567 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.5EPSS: 0%CPEs: 59EXPL: 0

Cobbler before 1.6.1 does not properly determine whether an installation has the default password, which makes it easier for attackers to obtain access by using this password. Cobbler, en versiones anteriores a la 1.6.1, no determina de manera apropiada si una instalación tiene la contraseña por defecto, lo que facilita a los atacantes obtener acceso usando esta contraseña. • http://people.fedoraproject.org/~shenson/cobbler/cobbler-2.0.8.tar.gz https://exchange.xforce.ibmcloud.com/vulnerabilities/64734 • CWE-255: Credentials Management Errors •

CVSS: 9.0EPSS: 0%CPEs: 42EXPL: 0

The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules. La interfaz web en Cobbler (CobblerWeb) anterior a v1.29, permite a usuarios autenticados remotamente ejecutar código Python de su elección en cobblerd, mediante la edición de la plantilla "Cheetah kickstart" a los módulos "import Python" arbitrarios. • http://freshmeat.net/projects/cobbler/releases/288374 http://osvdb.org/50291 http://secunia.com/advisories/32737 http://secunia.com/advisories/32804 http://www.securityfocus.com/bid/32317 https://exchange.xforce.ibmcloud.com/vulnerabilities/46625 https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00462.html https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00485.html • CWE-264: Permissions, Privileges, and Access Controls •