5
CVSSv2

CVE-2014-7819

Published: 08/11/2014 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in server.rb in Sprockets prior to 2.0.5, 2.1.x prior to 2.1.4, 2.2.x prior to 2.2.3, 2.3.x prior to 2.3.3, 2.4.x prior to 2.4.6, 2.5.x prior to 2.5.1, 2.6.x and 2.7.x prior to 2.7.1, 2.8.x prior to 2.8.3, 2.9.x prior to 2.9.4, 2.10.x prior to 2.10.2, 2.11.x prior to 2.11.3, 2.12.x prior to 2.12.3, and 3.x prior to 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote malicious users to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sprockets project sprockets 2.6.0

sprockets project sprockets

sprockets project sprockets 3.0.0

Vendor Advisories

Multiple directory traversal vulnerabilities in serverrb in Sprockets before 205, 21x before 214, 22x before 223, 23x before 233, 24x before 246, 25x before 251, 26x and 27x before 271, 28x before 283, 29x before 294, 210x before 2102, 211x before 2113, 212x before 2123, and 3x before 300beta3, ...