CVE-2006-4111Code Injection in Rails

CWE-94Code Injection7 documents5 sources
Severity
7.5HIGHNVD
EPSS
4.0%
top 11.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateOct 24

Description

Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages4 packages

RubyGemsrubyonrails/rails1.1.01.1.6
Debianrubyonrails/rails< 1.1.5-1+3
NVDrubyonrails/rails22 versions+21

Patches

🔴Vulnerability Details

5
GHSA
Ruby on Rails vulnerable to code injection2017-10-24
OSV
Ruby on Rails vulnerable to code injection2017-10-24
GHSA
Rails Denial of Service vulnerability2017-10-24
OSV
CVE-2006-4111: Ruby on Rails before 12006-08-14
CVEList
CVE-2006-4111: Ruby on Rails before 12006-08-14

📋Vendor Advisories

1
Debian
CVE-2006-4111: rails - Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "se...2006
CVE-2006-4111 — Code Injection in Rubyonrails Rails | cvebase