Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Foreman 代码注入漏洞
Vulnerability Description
Foreman是一套用于物理和虚拟服务器中的生命周期管理工具。该工具提供服务开通、配置管理以及报告状态等功能。 Foreman 1.2.0-rc1及之前的版本存在代码注入漏洞。远程经过授权的攻击者可通过控制器名称属性利用该漏洞以特权创建书签执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A