Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rvpq-5xqx-pfpp

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Ruby on Rails vulnerable to code injection

Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.

Пакеты

Наименование

rails

rubygems
Затронутые версииВерсия исправления

>= 1.1.0, < 1.1.6

1.1.6

EPSS

Процентиль: 82%
0.01893
Низкий

Дефекты

CWE-94

Связанные уязвимости

ubuntu
около 19 лет назад

Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.

nvd
около 19 лет назад

Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.

debian
около 19 лет назад

Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby cod ...

EPSS

Процентиль: 82%
0.01893
Низкий

Дефекты

CWE-94