Ruby on Rails < 1.2.6 Cookie Related Session Fixation

Medium Nessus Network Monitor Plugin ID 4299


The remote server can be used to attack user authentication data.


The remote server is running the Ruby on Rails web application.
This version of Rails is reported to be vulnerable to a flaw in the way that it handles authentication data. Allegedly, the 'lib/action_controller/cgi_process.rb' script is vulnerable to a flaw that would allow an attacker to steal cookie data. An attacker could then use this data to gain access to the application with the user's credentials.


Upgrade to version 1.2.6 or higher.

Plugin Details

Severity: Medium

ID: 4299

Family: Web Servers

Published: 2007/11/27

Modified: 2016/01/21

Dependencies: 1442, 4246

Risk Information

Risk Factor: Medium


Base Score: 5.8

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

Temporal Vector: CVSS2#E:F/RL:OF/RC:C


Base Score: 4.8

Temporal Score: 4.5


Temporal Vector: CVSS3#E:F/RL:O/RC:C

Reference Information

CVE: CVE-2007-6077

BID: 26598