CVE-2014-0057

The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remote attackers to execute arbitrary methods via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cloudforms_3.0_management_engine:5.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms:3.0:*:*:*:*:*:*:*

Information

Published : 2014-03-18 17:02

Updated : 2014-03-19 14:03


NVD link : CVE-2014-0057

Mitre link : CVE-2014-0057


JSON object : View

Products Affected

redhat

  • cloudforms
  • cloudforms_3.0_management_engine
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')