Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-2235 | First vendor Publication | 2010-12-09 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:S/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 8.5 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 6.8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2235 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
68883 | Cobbler on Red Hat template_api.py Kickstart Template File Arbitrary Code Exe... Cobbler on Red Hat contains a flaw related to template_api.py's failure to disable the Cheetah template engine's capability to execute Python statements contained in templates. The issue is triggered when a remote, authenticated administrator uses a crafted kickstart template file, allowing for the execution of arbitrary code. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-10-18 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2010-0775.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:06:45 |
|
2024-11-28 12:22:11 |
|
2023-02-13 09:29:04 |
|
2023-02-02 21:28:50 |
|
2021-05-04 12:11:45 |
|
2021-04-22 01:12:17 |
|
2020-05-23 01:42:13 |
|
2020-05-23 00:25:57 |
|
2014-02-17 10:55:58 |
|
2013-05-10 23:27:00 |
|