Total vulnerabilities in the database
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
Software | From | Fixed in |
---|---|---|
theforeman / foreman | 0.2 | 0.2.x |
theforeman / foreman | 0.4.1 | 0.4.1.x |
theforeman / foreman | 0.3 | 0.3.x |
theforeman / foreman | - | 1.0.x |
theforeman / foreman | 0.1 | 0.1.x |
theforeman / foreman | 0.4 | 0.4.x |