Title : Ruby WEBrick Library Multiple Remote Directory Traversal Vulnerabilities VUPEN ID : VUPEN/ADV-2008-0787 CVE ID : CVE-2008-1145
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-06
Technical Description
Multiple vulnerabilities have been identified in Ruby, which could be exploited by remote attackers to bypass security restrictions and disclose sensitive information. These issues are caused by input validation errors in the WEBrick library when publishing files using "WEBrick::HTTPServlet::FileHandler" or "WEBrick::HTTPServer.new" with the ":DocumentRoot" option, which could be exploited to conduct directory traversal attacks and disclose the contents of arbitrary files.