CVE-2007-5379
Published Oct 19, 2007Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via th…
Vendor/product archive
2 CVEs tagged to david_hansson / ruby_on_rails — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via th…
Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessi…