Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mongrel 'DirHandler' Class Directory Traversal Information Disclosure Vulnerability

Mongrel is prone to an information-disclosure vulnerability because it fails to sufficiently sanitize user-supplied input.

An attacker can exploit this issue to view sensitive files within the context of the webserver process. Information obtained may lead to other attacks.

This issue affects Mongrel 1.0.4 and versions prior to 1.1.3.







 

Privacy Statement
Copyright 2009, SecurityFocus