Incomplete blacklist vulnerability in action_power.py in Cobbler 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) username or (2) password fields to the power_system method in the xmlrpc API.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cobbler | Michael_dehaan | 2.2.0 (including) | 2.2.0 (including) |
| Red Hat Network Satellite Server v 5.4 | RedHat | cobbler-0:2.0.7-14.6.el5sat | * |
| Cobbler | Ubuntu | artful | * |
| Cobbler | Ubuntu | natty | * |
| Cobbler | Ubuntu | oneiric | * |
| Cobbler | Ubuntu | precise | * |
| Cobbler | Ubuntu | quantal | * |
| Cobbler | Ubuntu | raring | * |
| Cobbler | Ubuntu | saucy | * |
| Cobbler | Ubuntu | utopic | * |
| Cobbler | Ubuntu | vivid | * |
| Cobbler | Ubuntu | wily | * |
| Cobbler | Ubuntu | yakkety | * |
| Cobbler | Ubuntu | zesty | * |
| Maas-provision | Ubuntu | precise | * |