Linux Distros Unpatched Vulnerability : CVE-2018-1000225
Discription

image
The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web that can result in Privilege escalation to admin.. This attack appear to be exploitable via network connectivity. Sending unauthenticated JavaScript payload to the Cobbler XMLRPC API (/cobbler_api). (CVE-2018-1000225) Note that Nessus relies on the presence of the package as reported by the…Read More

Back to Main

Subscribe for the latest news: