VendorsDavid Hanssonruby_on_railsall versions
Vulnerabilities

David Hansson Ruby On Rails

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2007-5380
Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions."
Published 2007-10-19 · Modified
6.8EPSS 0.036
CVE-2007-5379
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses XmlSimple (XML::Simple) unsafely, as demonstrated by reading passwords from the Pidgin (Gaim) .purple/accounts.xml file.
Published 2007-10-19 · Modified
5.0EPSS 0.040