Sploitus

CVE-2019-5420

25 known exploits for CVE-2019-5420

A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.

Affected products
Alt Linux, Ruby On Rails, Suse
Rubyonrails Rails
< 5.2.2.1, 6.0.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
92.1% (100th percentile)
Weakness
CWE-77, CWE-330
NVD status
Modified
Published
2019-03-27
CVE-2019-5420 at NVD
Authoritative description, scoring and affected products

25 known exploits for CVE-2019-5420

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2019-5420
2026-08-28 KitPloitKITPLOIT
CVE-2019-5420
2026-08-28 KitPloitKITPLOIT
CVE-2019-5420
2026-08-28 KitPloitKITPLOIT
CVE-2019-5420
2026-08-28 KitPloitKITPLOIT
CVE-2019-5420
2026-08-28 KitPloitKITPLOIT
Rails-doubletap-RCE
2026-08-28 KitPloitKITPLOIT
CVE-2019-5420-PoC
2026-08-27 KitPloitKITPLOIT
cve-2019-5420
2026-08-27 KitPloitKITPLOIT
CVE-2019-5420.rb
2026-08-27 KitPloitKITPLOIT
ruby-RCE-CVE-2019-5420-
2026-08-27 KitPloitKITPLOIT
cve-2019-5420-POC
2026-08-26 KitPloitKITPLOIT
CVE-2019-5420
2026-08-26 KitPloitKITPLOIT
CVE-2019-5420-RCE
2026-08-25 KitPloitKITPLOIT
Exploit for Command Injection in Rubyonrails Rails
2022-07-02 laffrayGITHUB
Exploit for Command Injection in Rubyonrails Rails
2021-09-06 j4k0mGITHUB
Exploit for Command Injection in Rubyonrails Rails
2021-09-06 RyouYooGITHUB
Exploit for Command Injection in Rubyonrails Rails
2021-05-11 scumdestroyGITHUB
Exploit for Command Injection in Rubyonrails Rails
2021-01-20 EremielGITHUB
Ruby On Rails DoubleTap Development Mode secret_key_base Remote Code Execution Exploit
2019-05-02 metasploitZDTRuby
Ruby On Rails - DoubleTap Development Mode secret_key_base Remote Code Execution (Metasploit)
2019-05-02 MetasploitEXPLOITDBRuby
Ruby On Rails DoubleTap Development Mode secret_key_base Remote Code Execution
2019-05-01 sinn3rPACKETSTORMRuby
Immunity Canvas: RAILS_ACTIVESTORAGE_RCE
2019-03-27 Immunity CanvasCANVAS
Exploit for Path Traversal in Rubyonrails Rails
2019-03-23 mpgnGITHUB
Exploit for Command Injection in Rubyonrails Rails
2019-03-21 knqyf263GITHUB
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability
2019-03-13 ooooooo_q, mpgn, sinn3r <sinn3r@metasploit.com>METASPLOITRuby