Vulnerability Details CVE-2008-1145
Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c" (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.77
EPSS Ranking 98.9%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2008-1145
-
cpe:2.3:a:ruby-lang:ruby:1.8.0
-
cpe:2.3:a:ruby-lang:ruby:1.8.1
-
cpe:2.3:a:ruby-lang:ruby:1.8.2
-
cpe:2.3:a:ruby-lang:ruby:1.8.3
-
cpe:2.3:a:ruby-lang:ruby:1.8.4
-
cpe:2.3:a:ruby-lang:ruby:1.8.5
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.1
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.10
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.100
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.101
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.102
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.103
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.104
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.105
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.106
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.107
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.108
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.109
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.11
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.110
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.111
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.113
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.114
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.12
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.13
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.14
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.15
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.16
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.17
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.18
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.19
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.2
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.20
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.21
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.22
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.23
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.24
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.25
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.26
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.27
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.28
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.29
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.3
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.30
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.31
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.32
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.33
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.34
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.35
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.36
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.37
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.39
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.4
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.40
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.41
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.42
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.43
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.44
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.45
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.46
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.47
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.48
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.49
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.5
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.51
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.52
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.53
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.54
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.55
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.56
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.57
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.58
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.59
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.6
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.60
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.61
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.62
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.63
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.64
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.65
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.66
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.67
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.68
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.69
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.7
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.70
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.71
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.72
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.73
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.74
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.75
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.76
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.77
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.78
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.79
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.8
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.80
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.81
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.82
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.83
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.84
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.85
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.86
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.87
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.88
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.89
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.9
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.90
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.91
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.92
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.93
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.94
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.95
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.96
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.97
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.98
-
cpe:2.3:a:ruby-lang:ruby:1.8.5.99
-
cpe:2.3:a:ruby-lang:ruby:1.8.6
-
cpe:2.3:a:ruby-lang:ruby:1.8.6-26
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.1
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.10
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.100
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.101
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.102
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.103
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.104
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.105
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.106
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.107
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.109
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.110
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.111
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.112
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.113
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.12
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.13
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.14
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.15
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.16
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.17
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.18
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.19
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.2
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.20
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.21
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.22
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.23
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.24
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.25
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.26
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.27
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.30
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.31
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.32
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.33
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.34
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.35
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.36
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.37
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.38
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.39
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.4
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.40
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.41
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.42
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.43
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.44
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.45
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.46
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.47
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.48
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.49
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.5
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.50
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.51
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.52
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.53
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.54
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.55
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.56
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.57
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.58
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.59
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.6
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.60
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.63
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.64
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.65
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.66
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.67
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.68
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.69
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.7
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.70
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.72
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.73
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.74
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.75
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.76
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.77
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.78
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.79
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.8
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.80
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.81
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.82
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.83
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.84
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.85
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.86
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.87
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.88
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.89
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.9
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.90
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.91
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.92
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.93
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.94
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.95
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.96
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.97
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.98
-
cpe:2.3:a:ruby-lang:ruby:1.8.6.99
-
cpe:2.3:a:ruby-lang:ruby:1.9.0
-
cpe:2.3:a:ruby-lang:ruby:1.9.0.1
-
cpe:2.3:a:ruby-lang:webrick:-
-
cpe:2.3:o:fedoraproject:fedora:7
-
cpe:2.3:o:fedoraproject:fedora:8