Ruby on Rails(Rails)是Rails核心团队开发维护的一套基于Ruby语言的开源Web应用框架,它是由大卫-海纳梅尔-韩森从美国37signals公司的项目管理工具Basecamp里分离出来的。Action View是其中的一个用于渲染视图并可以在任何Ruby代码库中使用的独立代码库。 Ruby on Rails的Action View中存在目录遍历漏洞。远程攻击者可借助应用程序对‘render’方法的无限制使用和路径名中的目录遍历字符‘..’利用该漏洞读取任意文件。以下版本受到影响:Ru
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/forced-request/rails-rce-cve-2016-0752 | POC Details |
| 2 | None | https://github.com/dachidahu/CVE-2016-0752 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2016-2386 | SAP NetWeaver J2EE Engine UDDI服务器SQL注入漏洞 | |
| CVE-2016-2387 | SAP NetWeaver 跨站脚本漏洞 | |
| CVE-2016-2388 | SAP Netweaver 信息泄露漏洞 | |
| CVE-2016-2389 | SAP NetWeaver Manufacturing Integration and Intelligence 目录遍历漏洞 | |
| CVE-2015-7576 | Ruby On Rails Action Controller 信息泄露漏洞 | |
| CVE-2015-7577 | Ruby on Rails Action Record 安全绕过漏洞 | |
| CVE-2015-7578 | Ruby on Rails rails-html-sanitizer gem 跨站脚本漏洞 | |
| CVE-2015-7579 | Ruby On Rails rails-html-sanitizer gem 跨站脚本漏洞 | |
| CVE-2015-7580 | Ruby on Rails rails-html-sanitizer gem 跨站脚本漏洞 | |
| CVE-2015-7581 | Ruby on Rails Action Pack 拒绝服务漏洞 | |
| CVE-2016-0751 | Ruby on Rails Action Pack 拒绝服务漏洞 | |
| CVE-2016-0753 | Ruby on Rails Active Model 安全绕过漏洞 |
No comments yet