CVE-2008-7248

Ruby on Rails <2.1.3 & <2.2.2 - CSRF

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-7248. PoCs published by p0deje.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Redmine <= 0.8.6, allowing an attacker to create an admin user via a crafted HTML form. The PoC automatically submits the form using JavaScript, bypassing user interaction.

Description

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

Exploits (1)

exploitdb WORKING POC VERIFIED
by p0deje · textremotelinux
https://www.exploit-db.com/exploits/33402

This exploit demonstrates a CSRF vulnerability in Redmine <= 0.8.6, allowing an attacker to create an admin user via a crafted HTML form. The PoC automatically submits the form using JavaScript, bypassing user interaction.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Redmine <= 0.8.6
No auth needed
Prerequisites: Victim must visit the malicious HTML page · Redmine instance must be vulnerable (no CSRF token protection)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/11/28/1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36600
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2544
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/12/02/2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38915

Scores

EPSS 0.1141
EPSS Percentile 93.8%

Details

CWE
CWE-20
Status published
Products (6)
rubygems/actionpack 2.1.0 - 2.1.3RubyGems
rubyonrails/rails 2.1.0
rubyonrails/rails 2.1.1
rubyonrails/rails 2.1.2
rubyonrails/rails 2.2.0
rubyonrails/rails 2.2.1
Published Dec 16, 2009
Tracked Since Feb 18, 2026