exploits , vulnerabilities , articles , Ruby WEBrick Remote Directory Traversal and Information Disclosure Vulnerabilities
| Title |
Ruby WEBrick Remote Directory Traversal and Information Disclosure Vulnerabilities |
| Published |
2008-03-06-12:00AM |
| Updated |
2008-03-25-10:49PM |
| Class |
Unknown |
| CVE |
CVE-2008-1145 |
| Remote |
Yes |
| Local |
No |
| Credit |
Alexandr Polyakov and Stas Svistunovich of Digital Security Research Group reported these issues to the vendor. |
| Vulnerable |
Yukihiro Matsumoto Ruby 1.9 Yukihiro Matsumoto Ruby 1.8.6 Yukihiro Matsumoto Ruby 1.8.5 Yukihiro Matsumoto Ruby 1.8.5 Yukihiro Matsumoto Ruby 1.8.4 Yukihiro Matsumoto Ruby 1.8.3 Yukihiro Matsumoto Ruby 1.8.2 pre4 Gentoo Linux Yukihiro Matsumoto Ruby 1.8.2 pre3 Gentoo Linux Yukihiro Matsumoto Ruby 1.8.2 pre2 Yukihiro Matsumoto Ruby 1.8.2 pre1 Yukihiro Matsumoto Ruby 1.8.2 RedHat Fedora Core4 RedHat Fedora Core3 Yukihiro Matsumoto Ruby 1.8.1 RedHat Fedora Core3 RedHat Fedora Core2 Yukihiro Matsumoto Ruby 1.8 RedHat Fedora Core3 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Yukihiro Matsumoto Ruby 1.6.8 Yukihiro Matsumoto Ruby 1.6.7 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia64 Debian Linux 3.0 ia32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Yukihiro Matsumoto Ruby 1.6 rPath rPath Linux 1 rPath Appliance Platform Linux Service 1 RedHat Fedora 8 0 RedHat Fedora 7 0 Metasploit Project Metasploit Framework 3.1 Metasploit Project Metasploit Framework 3.0
|
| Not Vulnerable |
Yukihiro Matsumoto Ruby 1.9 -1 Yukihiro Matsumoto Ruby 1.8.6 -p114 Yukihiro Matsumoto Ruby 1.8.5 -p115
|
| Code |
The following proof-of-concept URI is available for the directory-traversal vulnerability:http://www.example.com/..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c/boot.ini |
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Fri, 18 Dec 2009 19:09:04 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www .vidiy include/ad sub7 malika she level_15 o cgi:irc j...oolbar sexe un ho www.ttjiud j...oolbar v2001.78rh news for C news for c search/exp Sexe araby Crack+Data WESTELL Qawwali maxcpm.inf x org WWW.PLAYWO addentry.p Fat pussy. Sexe araby Microsoft phpnuke 2. dragon fab www.mqdm.n vBulletin Linux 2.6. OSC www.mqdm.n phpBB port mambo Remo www.Sexyim transversa www. Sexi Www.BP FIL news for c modperl shop342756 Seksi c...form H& max Woman koobi-cms Www.sex se news for c six video
|