Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2019-5420
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Ruby on Rails 安全特征问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Ruby on Rails是Rails团队的一套基于Ruby语言的开源Web应用框架。 Ruby on Rails中存在安全特征问题漏洞。远程攻击者可利用该漏洞在受影响的系统上执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Railshttps://github.com/rails/rails 5.2.2.1 -
II. Public POCs for CVE-2019-5420
#POC DescriptionSource LinkShenlong Link
1CVE-2019-5420 (Ruby on Rails)https://github.com/knqyf263/CVE-2019-5420POC Details
2cve-2019-5420https://github.com/cved-sources/cve-2019-5420POC Details
3Nonehttps://github.com/AnasTaoutaou/CVE-2019-5420POC Details
4Nonehttps://github.com/Eremiel/CVE-2019-5420POC Details
5POC Exploit written in Rubyhttps://github.com/scumdestroy/CVE-2019-5420.rbPOC Details
6A vulnerability can allow an attacker to guess the automatically generated development mode secret token.https://github.com/j4k0m/CVE-2019-5420POC Details
7Nonehttps://github.com/mmeza-developer/CVE-2019-5420-RCEPOC Details
8Nonehttps://github.com/CyberSecurityUP/CVE-2019-5420-POCPOC Details
9Exploit for the Rails CVE-2019-5420https://github.com/trickstersec/CVE-2019-5420POC Details
10 Exploit in Rails Development Mode. With some knowledge of a target application it is possible for an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.https://github.com/PenTestical/CVE-2019-5420POC Details
11Ruby反序列化命令执行漏洞(CVE-2019-5420)-vulfocus通关版https://github.com/laffray/ruby-RCE-CVE-2019-5420-POC Details
12cve-2019-5420 POC simple ruby scripthttps://github.com/WildWestCyberSecurity/cve-2019-5420-POCPOC Details
13 A PoC of CVE-2019-5420 I made for PentesterLab https://github.com/sealldeveloper/CVE-2019-5420-PoCPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2019-5420
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2019-5420

No comments yet


Leave a comment