Ruby on Rails Routing Code URL Code Evaluation DoS

high Nessus Plugin ID 22204

Synopsis

The remote web server is affected by a code evaluation issue.

Description

The remote web server appears to be using a version of Ruby on Rails, an open source web framework, that has a flaw in its routing code that can lead to the evaluation of Ruby code through the URL. Successful exploitation of this issue can result in a denial of service or even data loss.

Solution

Either apply the appropriate patch referenced in the vendor advisory above or upgrade to Ruby on Rails 1.1.6 or later.

See Also

http://www.nessus.org/u?097ad1d4

Plugin Details

Severity: High

ID: 22204

File Name: rails_routing_code_eval.nasl

Version: 1.21

Type: remote

Family: CGI abuses

Published: 8/14/2006

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:rubyonrails:ruby_on_rails

Exploit Ease: No exploit is required

Vulnerability Publication Date: 8/10/2006

Reference Information

CVE: CVE-2006-4112

BID: 19454