Skip to content

Known CVE

Ruby On Rails - Local File Inclusion

Ruby On Rails is vulnerable to local file inclusion caused by secondary decoding in Sprockets 3.7.1 and lower versions. An attacker can use %252e%252e/ to access the root directory and read or execute any file on the target server.

CVE-2018-3760

High2018CVSS 7.5CWE-200CWE-22

cve2018 · rails · lfi · ruby · vulhub · seclists · redhat · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website