Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-0262

Опубликовано: 08 фев. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."

РелизСтатусПримечание
devel

released

1.5.2-1
esm-infra-legacy/trusty

released

1.5.2-1
hardy

DNE

lucid

DNE

oneiric

DNE

precise

not-affected

1.3.5-1
quantal

ignored

end of life
raring

ignored

end of life
saucy

released

1.5.2-1
trusty

released

1.5.2-1

Показывать по

EPSS

Процентиль: 74%
0.00826
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 13 лет назад

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."

nvd
почти 13 лет назад

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."

debian
почти 13 лет назад

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before ...

github
больше 8 лет назад

Rack Vulnerable to Path Traversal

EPSS

Процентиль: 74%
0.00826
Низкий

4.3 Medium

CVSS2