Total vulnerabilities in the database
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.
Software | From | Fixed in |
---|---|---|
cobbler_project / cobbler | 2.6.0 | 2.6.11.x |
redhat / satellite | 5.7 | 5.7.x |
redhat / satellite | 5.6 | 5.6.x |
redhat / satellite | 5.8 | 5.8.x |
![]() |
2.6.0 | 3.0.0 |