Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106423
Category:Web application abuses
Title:Foreman 0.2 < 1.10.4, 1.11.x < 1.11.2 RCE Vulnerability
Summary:Foreman is prone to a remote code execution (RCE); vulnerability.
Description:Summary:
Foreman is prone to a remote code execution (RCE)
vulnerability.

Vulnerability Insight:
The smart proxy TFTP API is vulnerable to arbitrary remote
code execution, as it passes untrusted user input (the PXE template type) to the eval() function
causing it to be executed.

Affected Software/OS:
Foreman version 0.2 prior to 1.10.4 and 1.11.x prior to
1.11.2.

Solution:
Update to version 1.10.4, 1.11.2 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-3728
RHBA-2016:1501
https://access.redhat.com/errata/RHBA-2016:1501
[oss-security] 20160519 CVE-2016-3728: remote code execution in Foreman smart proxy TFTP API
http://www.openwall.com/lists/oss-security/2016/05/19/2
http://projects.theforeman.org/issues/14931
http://theforeman.org/security.html#2016-3728
https://github.com/theforeman/smart-proxy/commit/eef532aa668d656b9d61d9c6edf7c2505f3f43c7
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.