CVE-2014-125033

A vulnerability was found in rails-cv-app. It has been rated as problematic. Affected by this issue is some unknown functionality of the file app/controllers/uploaded_files_controller.rb. The manipulation with the input ../../../etc/passwd leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. The patch is identified as 0d20362af0a5f8a126f67c77833868908484a863. It is recommended to apply a patch to fix this issue. VDB-217178 is the identifier assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rails-cv-app_project:rails-cv-app:*:*:*:*:*:*:*:*

History

11 Apr 2024, 00:51

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en Rails-cv-app. Ha sido calificada como problemática. Una función desconocida del archivo app/controllers/uploaded_files_controller.rb es afectada por este problema. La manipulación con la entrada ../../../etc/passwd conduce al path traversal: '../filedir'. El exploit ha sido divulgado al público y puede utilizarse. El parche se identifica como 0d20362af0a5f8a126f67c77833868908484a863. Se recomienda aplicar un parche para solucionar este problema. VDB-217178 es el identificador asignado a esta vulnerabilidad.

29 Feb 2024, 01:14

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-02 08:15

Updated : 2024-05-17 00:58


NVD link : CVE-2014-125033

Mitre link : CVE-2014-125033

CVE.ORG link : CVE-2014-125033


JSON object : View

Products Affected

rails-cv-app_project

  • rails-cv-app
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-24

Path Traversal: '../filedir'