6.4
CVSSv2

CVE-2014-4507

Published: 20/06/2014 Updated: 23/06/2014
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in Smart-Proxy in Foreman prior to 1.4.5 and 1.5.x prior to 1.5.1 allows remote malicious users to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

theforeman foreman 1.5.0

theforeman foreman

theforeman foreman 1.4.3

theforeman foreman 1.4.1

theforeman foreman 1.4.2

theforeman foreman 1.4.0