RDoc是针对Ruby源代码的文档系统。 Ruby中使用的RDoc 2.3.0至3.12版本以及4.0.0.preview2.1之前的4.x版本中的darkfish.js中存在漏洞,该漏洞源于程序没有正确生成文档。通过特制的URL,远程攻击者利用该漏洞进行跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2012-5604 | Red Hat CloudFroms 权限许可和访问控制漏洞 | |
| CVE-2013-0709 | dopvSTAR* 跨站脚本漏洞 | |
| CVE-2013-0708 | dopvCOMET* 跨站脚本漏洞 | |
| CVE-2013-0707 | JustSystems 多款产品未明任意代码执行漏洞 | |
| CVE-2013-0184 | Rack 资料不足漏洞 | |
| CVE-2013-0183 | Rack 缓冲区错误漏洞 | |
| CVE-2013-0162 | Ruby 权限许可和访问控制问题漏洞 | |
| CVE-2012-6116 | Katello 本地安全绕过漏洞 | |
| CVE-2012-6109 | Rack 安全漏洞 | |
| CVE-2011-2479 | Linux Kernel 本地拒绝服务漏洞 | |
| CVE-2012-5561 | Katello 不安全文件权限漏洞 | |
| CVE-2012-1568 | Linux Kernel ASLR安全绕过漏洞 | |
| CVE-2013-0228 | Linux Kernel 本地权限提升漏洞 | |
| CVE-2011-3638 | Linux Kernel ‘fs/ext4/extents.c’拒绝服务漏洞 | |
| CVE-2011-2905 | Linux Kernel 'perf'工具本地权限提升漏洞 | |
| CVE-2011-2491 | Linux Kernel NFS文件锁定拒绝服务漏洞 | |
| CVE-2011-1182 | Linux kernel ‘kernel/signal.c’通信码欺骗本地拒绝服务漏洞 | |
| CVE-2011-1019 | Linux kernel ‘dev_load’函数安全漏洞 |
No comments yet