CVE-2013-0262
- EPSS 0.83%
- Published 08.02.2013 20:55:01
- Last modified 11.04.2025 00:51:21
rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that...
CVE-2013-0263
- EPSS 5.28%
- Published 08.02.2013 20:55:01
- Last modified 11.04.2025 00:51:21
Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack...
- EPSS 1.28%
- Published 30.12.2011 01:55:01
- Last modified 11.04.2025 00:51:21
Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption...