Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:1943
HistoryJan 26, 2016 - 5:48 a.m.

Remote Code Execution (RCE) And Information Disclosure

2016-01-2605:48:59
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.974 High

EPSS

Percentile

99.9%

Actionpack is vulnerable to information disclosure and remote code execution. This vulnerability affects applications which pass user input directly into the render method in an action view controller without verification. Using this vulnerability, attackers can render files from outside the view directory and potentially perform remote code execution.