Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-0752
Description:Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2016.604   1.3.6.1.4.1.25623.1.0.807435  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-0752
BugTraq ID: 81801
http://www.securityfocus.com/bid/81801
Debian Security Information: DSA-3464 (Google Search)
http://www.debian.org/security/2016/dsa-3464
https://www.exploit-db.com/exploits/40561/
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178069.html
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178044.html
http://www.openwall.com/lists/oss-security/2016/01/25/13
https://groups.google.com/forum/message/raw?msg=ruby-security-ann/335P1DcLG00/JXcBnTtZEgAJ
RedHat Security Advisories: RHSA-2016:0296
http://rhn.redhat.com/errata/RHSA-2016-0296.html
http://www.securitytracker.com/id/1034816
SuSE Security Announcement: SUSE-SU-2016:1146 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.html
SuSE Security Announcement: openSUSE-SU-2016:0363 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-02/msg00034.html
SuSE Security Announcement: openSUSE-SU-2016:0372 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.html




© 1998-2025 E-Soft Inc. All rights reserved.