CVE Database
/

CVE-2008-1891

Back to search

CVE-2008-1891

Published: Apr 18, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Directory traversal vulnerability in WEBrick in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2, when using NTFS or FAT filesystems, allows remote attackers to read arbitrary CGI files via a trailing (1) + (plus), (2) %2b (encoded plus), (3) . (dot), (4) %2e (encoded dot), or (5) %20 (encoded space) character in the URI, possibly related to the WEBrick::HTTPServlet::FileHandler and WEBrick::HTTPServer.new functionality and the :DocumentRoot option.

VendorProductVersions

n/a

n/a

affected
n/a

References

29794
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2008:017
vendor-advisory
x_refsource_SUSE
MDVSA-2008:141
vendor-advisory
x_refsource_MANDRIVA
31687
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-5649
vendor-advisory
x_refsource_FEDORA
MDVSA-2008:140
vendor-advisory
x_refsource_MANDRIVA
30831
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1245
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now