CVE-2012-5648: SQL Injection
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5648?
CVE-2012-5648 is considered a high severity vulnerability due to the potential for remote SQL command execution.
How do I fix CVE-2012-5648?
To fix CVE-2012-5648, update Foreman to version 1.0.2 or later.
What types of attacks are possible with CVE-2012-5648?
CVE-2012-5648 allows remote attackers to perform SQL injection attacks, which can lead to unauthorized data access or manipulation.
Which versions of Foreman are affected by CVE-2012-5648?
Versions of Foreman prior to 1.0.2, including 0.1 to 0.4.1, are affected by CVE-2012-5648.
Is CVE-2012-5648 a local or remote vulnerability?
CVE-2012-5648 is a remote vulnerability, allowing attackers to exploit it over the network without local access.