Web Hack List

Other nomination

Blog - RCE due to ShowExceptions

A Rails application left Rack ShowExceptions enabled in production, so a carriage return in a filename parameter triggered an exception page that printed the application secret token. With that token an attacker signs an arbitrary session cookie, which Rails deserializes into remote code execution, confirmed here by a curl callback.

Record

Researcher
Harsh Jaiswal
Published by
Harsh Jaiswal
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Harsh Jaiswal, first published at the original source. Preserved copies are kept so the citation survives its host.