Web Hack List

Other nomination

File Name Enumeration in Rails

A path traversal in the way Rails served static assets: a URL of the form //%5C../%5C../etc/passwd, using percent-encoded backslashes, escaped the document root. Existing and non-existing paths produced different responses, letting an attacker enumerate arbitrary server-side filenames. Fixed in a Rails security release after this report.

Record

Published by
HackerOne

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of HackerOne, first published at the original source. Preserved copies are kept so the citation survives its host.