NOMISEC-mpgn/CVE-2019-5418

NOMISEC WORKING POC
Exploit for CVE-2019-5418 - Ruby On Rails File Content Disclosure (
AI Analysis

This repository contains a working proof-of-concept for CVE-2019-5418, demonstrating file content disclosure in Ruby on Rails via crafted Accept headers. The exploit leverages a vulnerability in Action View's `render file:` functionality to read arbitrary files on the server.

Attack Type
info_leak
Complexity
trivial
Reliability
reliable
MITRE ATT&CK
T1083 - File and Directory Discovery T1119 - Automated Collection
Loading exploit code...
Download ZIP Password: eip
Source
Platform Nomisec
Type infoleak
Files 85
Stars 201
Forks 22
Last Push Apr 05, 2021
Vulnerability
CVE-2019-5418
Ruby On Rails File Content Disclosure (
HIGH KEV
CVSS 7.5