Vulnerabilities > Dell > Crowbar

DATE CVE VULNERABILITY TITLE RISK
2012-09-05 CVE-2012-3551 Cross-Site Scripting vulnerability in Dell Crowbar
Cross-site scripting (XSS) vulnerability in crowbar_framework/app/views/support/index.html.haml in the Crowbar barclamp in Crowbar, possibly 1.4 and earlier, allows remote attackers to inject arbitrary web script or HTML via the file parameter to /utils.
network
dell CWE-79
4.3
2012-09-05 CVE-2012-3537 Permissions, Privileges, and Access Controls vulnerability in Dell Crowbar
The Crowbar Ohai plugin (chef/cookbooks/ohai/files/default/plugins/crowbar.rb) in the Deployer Barclamp in Crowbar, possibly 1.4 and earlier, allows local users to execute arbitrary shell commands via vectors related to "insecure handling of tmp files" and predictable file names.
local
low complexity
dell CWE-264
4.6