Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-7819
Description:Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2015.0074   1.3.6.1.4.1.25623.1.0.869018   1.3.6.1.4.1.25623.1.0.869015  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-7819
[rubyonrails-security] 20141030 Arbitrary file existence disclosure in Sprockets (CVE-2014-7819)
https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJ
[rubyonrails-security] 20141030 [AMENDED] [CVE-2014-7819] Arbitrary file existence disclosure in Sprockets
https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJ
openSUSE-SU-2014:1502
http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.html
openSUSE-SU-2014:1504
http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.html
openSUSE-SU-2014:1513
http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.html
openSUSE-SU-2014:1514
http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.html




© 1998-2025 E-Soft Inc. All rights reserved.