CVE-2014-0130

Ruby on Rails Directory Traversal Vulnerability

Beschreibung

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

Schweregrad: HIGH

CVSS-Score: 7.5

Hersteller: Rails

Produkt: Ruby on Rails

CVE-Details werden geladen...