6.8
CVSSv2

CVE-2016-3728

Published: 20/05/2016 Updated: 12/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman prior to 1.10.4 and 1.11.x prior to 1.11.2 allows remote malicious users to execute arbitrary code via the PXE template type portion of the PATH_INFO to tftp/.

Vulnerable Product Search on Vulmon Subscribe to Product

theforeman foreman 1.11.0

theforeman foreman 1.11.1

theforeman foreman 1.10.3

Vendor Advisories

It was found that the “variant” parameter in the TFTP API of Foreman was passed to the eval() function An attacker could possibly use this flaw to execute arbitrary code with the privileges of the Foreman user ...