Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-1145
Description:Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c" (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option.
Test IDs: 1.3.6.1.4.1.25623.1.0.60561   1.3.6.1.4.1.25623.1.0.60562  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-1145
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
BugTraq ID: 28123
http://www.securityfocus.com/bid/28123
Bugtraq: 20080306 Re: [DSECRG-08-018] Ruby 1.8.6 (Webrick Httpd 1.3.1) Directory traversal file Download Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/489218/100/0/threaded
Bugtraq: 20080306 [DSECRG-08-018] Ruby 1.8.6 (Webrick Httpd 1.3.1) Directory traversal file Download Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/489205/100/0/threaded
Bugtraq: 20080325 rPSA-2008-0123-1 ruby (Google Search)
http://www.securityfocus.com/archive/1/490056/100/0/threaded
CERT/CC vulnerability note: VU#404515
http://www.kb.cert.org/vuls/id/404515
https://www.exploit-db.com/exploits/5215
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00338.html
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00354.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:141
http://www.mandriva.com/security/advisories?name=MDVSA-2008:142
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10937
RedHat Security Advisories: RHSA-2008:0897
http://www.redhat.com/support/errata/RHSA-2008-0897.html
http://www.securitytracker.com/id?1019562
http://secunia.com/advisories/29232
http://secunia.com/advisories/29357
http://secunia.com/advisories/29536
http://secunia.com/advisories/30802
http://secunia.com/advisories/31687
http://secunia.com/advisories/32371
SuSE Security Announcement: SUSE-SR:2008:017 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html
http://www.vupen.com/english/advisories/2008/0787
http://www.vupen.com/english/advisories/2008/1981/references
XForce ISS Database: ruby-webrick-directory-traversal(41010)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41010




© 1998-2024 E-Soft Inc. All rights reserved.