Lucene search

K
cvelistRedhatCVELIST:CVE-2008-1145
HistoryMar 04, 2008 - 11:00 p.m.

CVE-2008-1145

2008-03-0423:00:00
redhat
www.cve.org
1

6.6 Medium

AI Score

Confidence

High

0.22 Low

EPSS

Percentile

96.5%

Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash () path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) “…%5c” (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option.

References

6.6 Medium

AI Score

Confidence

High

0.22 Low

EPSS

Percentile

96.5%