Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| rails(RubyGems) | 1.1.0 | 1.1.6 | N/A |
CVSS Metrics