CVE Vulnerabilities

CVE-2006-4112

Published: Aug 14, 2006 | Modified: Aug 08, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Unspecified vulnerability in the dependency resolution mechanism in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or data loss, a different vulnerability than CVE-2006-4111.

Affected Software

Name Vendor Start Version End Version
Rails Rubyonrails 1.1.0 (including) 1.1.0 (including)
Rails Rubyonrails 1.1.1 (including) 1.1.1 (including)
Rails Rubyonrails 1.1.2 (including) 1.1.2 (including)
Rails Rubyonrails 1.1.3 (including) 1.1.3 (including)
Rails Rubyonrails 1.1.4 (including) 1.1.4 (including)
Rails Ubuntu dapper *
Rails Ubuntu upstream *

References