CVE-2008-1145
Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c" (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option.
- Ruby-lang Webrick
- All versions
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 27.8% (98th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2008-03-04
CVE-2008-1145 at NVD
1 known exploit for CVE-2008-1145
Proof-of-concept code and exploit modules indexed by Sploitus