Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.#{target_host}.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby VladTheEnterprising gem 安全漏洞
Vulnerability Description
Ruby VladTheEnterprising gem是软件开发者Michael L. Welles所研发的一个用于帮助用户使用Vlad(Ruby应用部署工具)管理企业环境的系列软件包。 Ruby VladTheEnterprising gem 0.2版本中的lib/vlad/dba/mysql.rb文件存在本地安全绕过漏洞。本地攻击者可通过对/tmp/my.cnf.#{target_host}实施符号链接攻击利用该漏洞对任意文件执行写入操作。
CVSS Information
N/A
Vulnerability Type
N/A