Ruby on Rails Routing Code URL Code Evaluation DoS

High Nessus Plugin ID 22204

Synopsis

The remote web server is affected by a code evaluation issue.

Description

The remote web server appears to be using a version of Ruby on Rails, an open source web framework, that has a flaw in its routing code that can lead to the evaluation of Ruby code through the URL. Successful exploitation of this issue can result in a denial of service or even data loss.

Solution

Either apply the appropriate patch referenced in the vendor advisory above or upgrade to Ruby on Rails 1.1.6 or later.

See Also

http://www.nessus.org/u?097ad1d4

Plugin Details

Severity: High

ID: 22204

File Name: rails_routing_code_eval.nasl

Version: 1.20

Type: remote

Family: CGI abuses

Published: 2006/08/14

Updated: 2018/11/15

Dependencies: 10107

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:rubyonrails:ruby_on_rails

Exploit Available: false

Exploit Ease: No exploit is required

Vulnerability Publication Date: 2006/08/10

Reference Information

CVE: CVE-2006-4112

BID: 19454