CVE-2014-4507
6.4
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:P
Exploitability: 10.0 / Impact: 4.9
Source: NVD
Description
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.
Affected (6)
Products: Theforeman: Foreman
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.4.4 |
References (2)
Timeline
No history available yet.