CVE-2012-2395
Cobbler < 2.6.0 - Remote Code Execution via Shell Metacharacters in XMLRPC Power System Credentials
Title source: llmDescription
Incomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.
References (9)
Core 9
Core References
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00000.html
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/23/4
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/53666
Exploit, Patch x_refsource_confirm
https://github.com/cobbler/cobbler/commit/6d9167e5da44eca56bdf42b5776097a6779aaadf
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/23/18
Issue Tracking x_refsource_misc
https://bugs.launchpad.net/ubuntu/+source/cobbler/+bug/978999
Issue Tracking x_refsource_confirm
https://github.com/cobbler/cobbler/issues/141
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00016.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/82458
Scores
EPSS
0.0556
EPSS Percentile
92.0%
Details
Status
published
Products (2)
michael_dehaan/cobbler
2.2.0
pypi/cobbler
0 - 2.6.0PyPI
Published
Jun 16, 2012
Tracked Since
Feb 18, 2026