Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-125033

Опубликовано: 02 янв. 2023
Источник: nvd
CVSS3: 3.5
CVSS3: 7.5
CVSS2: 2.7
EPSS Низкий

Описание

A vulnerability was found in rails-cv-app. It has been rated as problematic. Affected by this issue is some unknown functionality of the file app/controllers/uploaded_files_controller.rb. The manipulation with the input ../../../etc/passwd leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. The patch is identified as 0d20362af0a5f8a126f67c77833868908484a863. It is recommended to apply a patch to fix this issue. VDB-217178 is the identifier assigned to this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rails-cv-app_project:rails-cv-app:*:*:*:*:*:*:*:*
Версия до 2014-11-16 (исключая)

EPSS

Процентиль: 44%
0.0022
Низкий

3.5 Low

CVSS3

7.5 High

CVSS3

2.7 Low

CVSS2

Дефекты

CWE-24
CWE-22

Связанные уязвимости

CVSS3: 7.5
github
около 3 лет назад

A vulnerability was found in rails-cv-app. It has been rated as problematic. Affected by this issue is some unknown functionality of the file app/controllers/uploaded_files_controller.rb. The manipulation with the input ../../../etc/passwd leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. The name of the patch is 0d20362af0a5f8a126f67c77833868908484a863. It is recommended to apply a patch to fix this issue. VDB-217178 is the identifier assigned to this vulnerability.

EPSS

Процентиль: 44%
0.0022
Низкий

3.5 Low

CVSS3

7.5 High

CVSS3

2.7 Low

CVSS2

Дефекты

CWE-24
CWE-22