CVE-2013-4386
published 2013-11-20CVE-2013-4386: Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.24%
65.7th percentile
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openstack | — | — |
| theforeman | foreman | <= 1.2.2 | — |
| theforeman | foreman | — | — |
| theforeman | foreman | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-28hw-8f4m-6fxw: Multiple SQL injection vulnerabilities in app/models/concerns/host_common
ghsa_unreviewed·2022-05-14
CVE-2013-4386 [HIGH] CWE-89 GHSA-28hw-8f4m-6fxw: Multiple SQL injection vulnerabilities in app/models/concerns/host_common
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
Red Hat
Foreman: host and host group parameter SQL injection
vendor_redhat·2013-10-07·CVSS 7.5
CVE-2013-4386 [HIGH] CWE-89 Foreman: host and host group parameter SQL injection
Foreman: host and host group parameter SQL injection
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
No detection rules found.
No public exploits indexed.
http://projects.theforeman.org/issues/3160http://rhn.redhat.com/errata/RHSA-2013-1522.htmlhttps://groups.google.com/forum/#%21topic/foreman-announce/GKMNXM66Z84http://projects.theforeman.org/issues/3160http://rhn.redhat.com/errata/RHSA-2013-1522.htmlhttps://groups.google.com/forum/#%21topic/foreman-announce/GKMNXM66Z84
2013-11-20
Published