Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-0449
Description:actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.
Test IDs: 1.3.6.1.4.1.25623.1.0.69466  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-0449
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057650.html
http://groups.google.com/group/rubyonrails-security/msg/04345b2e84df5b4f?dmode=source&output=gplain
http://securitytracker.com/id?1025061
http://secunia.com/advisories/43278
http://www.vupen.com/english/advisories/2011/0877




© 1998-2025 E-Soft Inc. All rights reserved.