{"id":"CVE-2008-6954","aliases":["PYSEC-2026-795"],"url":"https://o3.security/vulnerability/CVE-2008-6954","summary":"Cobbler Web Interface Kickstart Template Remote Privilege Escalation Vulnerability","details":"The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code with the root privileges in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.","published":"2022-05-17T02:10:02Z","modified":"2026-07-07T11:56:25.755338099Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"cobbler","fixedVersion":"1.2.9"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-6954"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46625"},{"type":"PACKAGE","url":"https://github.com/cobbler/cobbler"},{"type":"WEB","url":"https://web.archive.org/web/20111227125913/http://secunia.com/advisories/32804"},{"type":"WEB","url":"https://web.archive.org/web/20111227151912/http://secunia.com/advisories/32737"},{"type":"WEB","url":"https://web.archive.org/web/20200228143518/http://www.securityfocus.com/bid/32317"},{"type":"WEB","url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00462.html"},{"type":"WEB","url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00485.html"},{"type":"WEB","url":"http://freshmeat.net/projects/cobbler/releases/288374"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T11:56:25.755338099Z"}}