about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Ruby WEBrick Remote Directory Traversal and Information Disclosure Vulnerabilities


Title Ruby WEBrick Remote Directory Traversal and Information Disclosure Vulnerabilities
Published 2008-03-06-12:00AM
Updated 2008-03-25-10:49PM
Class Unknown
CVE   CVE-2008-1145
Remote  Yes
Local  No
Credit  Alexandr Polyakov and Stas Svistunovich of Digital Security Research Group reported these issues to the vendor.
Vulnerable  Yukihiro Matsumoto Ruby 1.9
Yukihiro Matsumoto Ruby 1.8.6
Yukihiro Matsumoto Ruby 1.8.5
Yukihiro Matsumoto Ruby 1.8.5
Yukihiro Matsumoto Ruby 1.8.4
Yukihiro Matsumoto Ruby 1.8.3
Yukihiro Matsumoto Ruby 1.8.2 pre4
Gentoo Linux
Yukihiro Matsumoto Ruby 1.8.2 pre3
Gentoo Linux
Yukihiro Matsumoto Ruby 1.8.2 pre2
Yukihiro Matsumoto Ruby 1.8.2 pre1
Yukihiro Matsumoto Ruby 1.8.2
RedHat Fedora Core4
RedHat Fedora Core3
Yukihiro Matsumoto Ruby 1.8.1
RedHat Fedora Core3
RedHat Fedora Core2
Yukihiro Matsumoto Ruby 1.8
RedHat Fedora Core3
Ubuntu Ubuntu Linux 5.0 4 powerpc
Ubuntu Ubuntu Linux 5.0 4 i386
Ubuntu Ubuntu Linux 5.0 4 amd64
Ubuntu Ubuntu Linux 4.1 ppc
Ubuntu Ubuntu Linux 4.1 ia64
Ubuntu Ubuntu Linux 4.1 ia32
Yukihiro Matsumoto Ruby 1.6.8
Yukihiro Matsumoto Ruby 1.6.7
Debian Linux 3.0 sparc
Debian Linux 3.0 s/390
Debian Linux 3.0 ppc
Debian Linux 3.0 mipsel
Debian Linux 3.0 mips
Debian Linux 3.0 m68k
Debian Linux 3.0 ia64
Debian Linux 3.0 ia32
Debian Linux 3.0 hppa
Debian Linux 3.0 arm
Debian Linux 3.0 alpha
Debian Linux 3.0
Yukihiro Matsumoto Ruby 1.6
rPath rPath Linux 1
rPath Appliance Platform Linux Service 1
RedHat Fedora 8 0
RedHat Fedora 7 0
Metasploit Project Metasploit Framework 3.1
Metasploit Project Metasploit Framework 3.0
Not Vulnerable  Yukihiro Matsumoto Ruby 1.9 -1
Yukihiro Matsumoto Ruby 1.8.6 -p114
Yukihiro Matsumoto Ruby 1.8.5 -p115
Code  The following proof-of-concept URI is available for the directory-traversal vulnerability:http://www.example.com/..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c/boot.ini
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 19:09:04 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www .vidiy include/ad sub7 malika she level_15 o cgi:irc j...oolbar sexe un ho www.ttjiud j...oolbar v2001.78rh news for C news for c search/exp Sexe araby Crack+Data WESTELL Qawwali maxcpm.inf x org WWW.PLAYWO addentry.p Fat pussy. Sexe araby Microsoft phpnuke 2. dragon fab www.mqdm.n vBulletin Linux 2.6. OSC www.mqdm.n phpBB port mambo Remo www.Sexyim transversa www. Sexi Www.BP FIL news for c modperl shop342756 Seksi c...form H& max Woman koobi-cms Www.sex se news for c six video