7.5
CVSSv2

CVE-2006-4111

Published: 14/08/2006 Updated: 08/08/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Ruby on Rails prior to 1.1.5 allows remote malicious users to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails ruby on rails 0.8.0

rubyonrails ruby on rails 0.9.0

rubyonrails ruby on rails 0.5.0

rubyonrails ruby on rails 0.5.6

rubyonrails rails 0.12.0

rubyonrails rails 0.13.0

rubyonrails rails 0.14.1

rubyonrails rails 0.11.0

rubyonrails rails 1.1.3

rubyonrails rails 1.1.2

rubyonrails rails 1.1.1

rubyonrails rails 1.1.0

rubyonrails rails 1.0.0

rubyonrails ruby on rails 0.5.7

rubyonrails ruby on rails 0.6.0

rubyonrails ruby on rails 0.6.5

rubyonrails ruby on rails 0.7.0

rubyonrails rails 0.9.2

rubyonrails rails 0.9.3

rubyonrails rails 0.9.4

rubyonrails rails 0.9.4.1

rubyonrails rails 0.13.1

rubyonrails rails 0.14.3

rubyonrails rails 0.14.2

rubyonrails rails 0.10.0

rubyonrails ruby on rails

rubyonrails ruby on rails 0.8.5

rubyonrails rails 0.9.1

rubyonrails rails 0.14.4

rubyonrails ruby on rails 0.5.5

rubyonrails rails 0.11.1

rubyonrails rails 0.12.1

rubyonrails rails 0.10.1