Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-0449

Опубликовано: 21 фев. 2011
Источник: ubuntu
Приоритет: low
CVSS2: 7.5

Описание

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.

РелизСтатусПримечание
dapper

not-affected

3.0.x only
devel

not-affected

3.0.x only
hardy

not-affected

3.0.x only
karmic

not-affected

3.0.x only
lucid

not-affected

3.0.x only
maverick

not-affected

3.0.x only
upstream

released

3.0.4

Показывать по

Ссылки на источники

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 15 лет назад

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.

debian
почти 15 лет назад

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x ...

github
больше 8 лет назад

actionpack allows remote attackers to bypass intended access restrictions

7.5 High

CVSS2