Skip to main content

Vendor/product archive

david_hansson / ruby_on_rails CVEs

Beta · best-effort

2 CVEs tagged to david_hansson / ruby_on_rails0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2007-5379

Published Oct 19, 2007

Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5380

Published Oct 19, 2007

Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1