Sploitus

CVE-2011-0449

1 known exploit for CVE-2011-0449

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.

Affected products
Ruby On Rails, Suse
Rubyonrails Rails
= 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
2.5% (84th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2011-02-21
CVE-2011-0449 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2011-0449

Proof-of-concept code and exploit modules indexed by Sploitus