Ruby on Rails Routing Code URL Code Evaluation DoS

high Nessus Plugin ID 22204


The remote web server is affected by a code evaluation issue.


The remote web server appears to be using a version of Ruby on Rails, an open source web framework, that has a flaw in its routing code that can lead to the evaluation of Ruby code through the URL. Successful exploitation of this issue can result in a denial of service or even data loss.


Either apply the appropriate patch referenced in the vendor advisory above or upgrade to Ruby on Rails 1.1.6 or later.

See Also

Plugin Details

Severity: High

ID: 22204

File Name: rails_routing_code_eval.nasl

Version: 1.21

Type: remote

Family: CGI abuses

Published: 8/14/2006

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information


Risk Factor: Medium

Score: 5.5


Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:rubyonrails:ruby_on_rails

Exploit Ease: No exploit is required

Vulnerability Publication Date: 8/10/2006

Reference Information

CVE: CVE-2006-4112

BID: 19454