RubyInstaller2是One-Click Project开源的一个用于 Windows 的基于 MSYS2 的 RubyInstaller。为 Windows 上的 Ruby-2.4 和更新版本提供了安装程序。 Rubyinstaller2 v3.1.2版本及之前版本存在安全漏洞,该漏洞源于安装目录 (C:RailsInstaller) 中存在不正确的访问控制。攻击者利用该漏洞通过覆盖目录中的二进制文件来执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-25857 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-25646 | 5.4 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2022-25887 | 5.3 MEDIUM | Regular Expression Denial of Service (ReDoS) |
| CVE-2022-36745 | LibreNMS 跨站脚本漏洞 | |
| CVE-2022-37173 | Gvim 安全漏洞 | |
| CVE-2022-36730 | Library Management System SQL注入漏洞 | |
| CVE-2022-36731 | Library Management System SQL注入漏洞 | |
| CVE-2022-36732 | Library Management System SQL注入漏洞 | |
| CVE-2022-36733 | Library Management System SQL注入漏洞 | |
| CVE-2022-36734 | Library Management System SQL注入漏洞 | |
| CVE-2022-36735 | Library Management System SQL注入漏洞 | |
| CVE-2022-36657 | Library Management System 跨站脚本漏洞 | |
| CVE-2022-36565 | WampServer 安全漏洞 | |
| CVE-2022-36746 | LibreNMS 跨站脚本漏洞 | |
| CVE-2022-36747 | Razor 跨站脚本漏洞 | |
| CVE-2022-36748 | PicUploader 跨站脚本漏洞 | |
| CVE-2022-36749 | RPi-Jukebox-RFID 操作系统命令注入漏洞 | |
| CVE-2022-37172 | MSYS2 安全漏洞 | |
| CVE-2021-46837 | Asterisk 代码问题漏洞 | |
| CVE-2022-36564 | Perl 安全漏洞 |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet