CVE-2006-4111
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
- Affected products
- Ruby On Rails
- Rubyonrails Rails
- = 0.9.1, 0.9.2, 0.9.3, 0.9.4, 0.9.4.1, 0.10.0, 0.10.1, 0.11.0, 0.11.1, 0.12.0, 0.12.1, 0.13.0, 0.13.1, 0.14.1, 0.14.2, 0.14.3, 0.14.4, 1.0.0, 1.1.0, 1.1.1, 1.1.2, 1.1.3
- Rubyonrails Ruby On Rails
- ≤ 1.1.4, 0.5.0, 0.5.5, 0.5.6, 0.5.7, 0.6.0, 0.6.5, 0.7.0, 0.8.0, 0.8.5, 0.9.0
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 2.3% (82th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2006-08-14
CVE-2006-4111 at NVD
No indexed exploits for CVE-2006-4111 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2006-4111 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.