Back to search
CVE-2006-4112
Published: Aug 14, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
21466
third-party-advisory
x_refsource_SECUNIA
21749
third-party-advisory
x_refsource_SECUNIA
19454
vdb-entry
x_refsource_BID
rubyonrails-url-code-execution(28364)
vdb-entry
x_refsource_XF
SUSE-SR:2006:021
vendor-advisory
x_refsource_SUSE
20060811 Security Vulnerability in Ruby on Rails 1.1.x
mailing-list
x_refsource_BUGTRAQ
GLSA-200608-20
vendor-advisory
x_refsource_GENTOO
VU#699540
third-party-advisory
x_refsource_CERT-VN
21424
third-party-advisory
x_refsource_SECUNIA
1016673
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now