CVE-2012-2395

Cobbler < 2.6.0 - Remote Code Execution via Shell Metacharacters in XMLRPC Power System Credentials

Title source: llm
STIX 2.1

Description

Incomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.

References (9)

Core 9
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/23/4
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53666
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/23/18
Issue Tracking x_refsource_confirm
https://github.com/cobbler/cobbler/issues/141
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/82458

Scores

EPSS 0.0556
EPSS Percentile 92.0%

Details

Status published
Products (2)
michael_dehaan/cobbler 2.2.0
pypi/cobbler 0 - 2.6.0PyPI
Published Jun 16, 2012
Tracked Since Feb 18, 2026