CVE-2006-4111
published 2006-08-14CVE-2006-4111: Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.21%
80.3th percentile
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 1.1.6-1 (bookworm) | rails 1.1.6-1 (bookworm) |
| debian | rails | < rails 1.1.5-1 (bookworm) | rails 1.1.5-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Rails Denial of Service vulnerability
ghsa·2017-10-24·CVSS 7.5
CVE-2006-4112 [HIGH] Rails Denial of Service vulnerability
Rails Denial of Service vulnerability
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.
GHSA
Ruby on Rails vulnerable to code injection
ghsa·2017-10-24·CVSS 7.5
CVE-2006-4111 [HIGH] CWE-94 Ruby on Rails vulnerable to code injection
Ruby on Rails vulnerable to code injection
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
OSV
Ruby on Rails vulnerable to code injection
osv·2017-10-24·CVSS 7.5
CVE-2006-4111 [HIGH] Ruby on Rails vulnerable to code injection
Ruby on Rails vulnerable to code injection
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
OSV
Rails Denial of Service vulnerability
osv·2017-10-24·CVSS 7.5
CVE-2006-4112 [HIGH] Rails Denial of Service vulnerability
Rails Denial of Service vulnerability
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.
OSV
CVE-2006-4112: Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1
osv·2006-08-14·CVSS 7.5
CVE-2006-4112 [HIGH] CVE-2006-4112: Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.
OSV
CVE-2006-4111: Ruby on Rails before 1
osv·2006-08-14·CVSS 7.5
CVE-2006-4111 [HIGH] CVE-2006-4111: Ruby on Rails before 1
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
Debian
CVE-2006-4112: rails - Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Ra...
vendor_debian·2006·CVSS 7.5
CVE-2006-4112 [HIGH] CVE-2006-4112: rails - Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Ra...
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.
Scope: local
bookworm: resolved (fixed in 1.1.6-1)
bullseye: resolved (fixed in 1.1.6-1)
forky: resolved (fixed in 1.1.6-1)
sid: resolved (fixed in 1.1.6-1)
trixie: resolved (fixed in 1.1.6-1)
Debian
CVE-2006-4111: rails - Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "se...
vendor_debian·2006·CVSS 7.5
CVE-2006-4111 [HIGH] CVE-2006-4111: rails - Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "se...
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
Scope: local
bookworm: resolved (fixed in 1.1.5-1)
bullseye: resolved (fixed in 1.1.5-1)
forky: resolved (fixed in 1.1.5-1)
sid: resolved (fixed in 1.1.5-1)
trixie: resolved (fixed in 1.1.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://blog.koehntopp.de/archives/1367-Ruby-On-Rails-Mandatory-Mystery-Patch.htmlhttp://secunia.com/advisories/21466http://secunia.com/advisories/21749http://securitytracker.com/id?1016673http://weblog.rubyonrails.org/2006/8/9/rails-1-1-5-mandatory-security-patch-and-other-tidbitshttp://www.gentoo.org/security/en/glsa/glsa-200608-20.xmlhttp://www.novell.com/linux/security/advisories/2006_21_sr.htmlhttp://www.securityfocus.com/bid/19454http://www.vupen.com/english/advisories/2006/3237http://blog.koehntopp.de/archives/1367-Ruby-On-Rails-Mandatory-Mystery-Patch.htmlhttp://secunia.com/advisories/21466http://secunia.com/advisories/21749http://securitytracker.com/id?1016673http://weblog.rubyonrails.org/2006/8/9/rails-1-1-5-mandatory-security-patch-and-other-tidbitshttp://www.gentoo.org/security/en/glsa/glsa-200608-20.xmlhttp://www.novell.com/linux/security/advisories/2006_21_sr.htmlhttp://www.securityfocus.com/bid/19454http://www.vupen.com/english/advisories/2006/3237
2006-08-14
Published