CVE-2008-1145
WEBrick <1.8.5-p115, 1.8.6-p114, 1.9-1.9.0-1 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1145. PoCs published by DSecRG.
AI-analyzed exploit summary This advisory describes a directory traversal vulnerability in Ruby's WEBrick HTTP server (CVE-2008-1145), allowing attackers to access private files via URL-encoded backslashes or bypass nondisclosure name filters on case-insensitive filesystems.
Description
Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c" (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option.
Exploits (1)
This advisory describes a directory traversal vulnerability in Ruby's WEBrick HTTP server (CVE-2008-1145), allowing attackers to access private files via URL-encoded backslashes or bypass nondisclosure name filters on case-insensitive filesystems.