It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cobbler project cobbler |
||
redhat satellite 5.7 |
||
redhat satellite 5.6 |
||
redhat satellite 5.8 |