CVE-2020-8163:CVE-2020-8163-在Rails中远程执行用户提供的本地名称的代码

上传者: 42151305 | 上传时间: 2025-12-27 18:34:32 | 文件大小: 36KB | 文件类型: ZIP
CVE-2020-8163 CVE-2020-8163-在Rails中远程执行用户提供的本地名称的代码 在Rails <5.0.1中远程执行用户提供的本地名称 5.0.1之前的Rails版本中存在一个漏洞,该漏洞将允许攻击者控制render调用的locals参数。 已为该漏洞分配了CVE标识符CVE-2020-8163。 受影响的版本:rails <5.0.1不受影响:不允许用户控制本地名称的应用程序。 固定版本:4.2.11.2 漏洞应用: 我包含了一个可用于测试目的的易受攻击的应用程序。 易受攻击的端点是: main/index

文件下载

资源详情

[{"title":"( 69 个子文件 36KB ) CVE-2020-8163:CVE-2020-8163-在Rails中远程执行用户提供的本地名称的代码","children":[{"title":"CVE-2020-8163-master","children":[{"title":"README.md <span style='color:#111;'> 669B </span>","children":null,"spread":false},{"title":"testapp","children":[{"title":".byebug_history <span style='color:#111;'> 260B </span>","children":null,"spread":false},{"title":"log","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":true},{"title":"public","children":[{"title":"500.html <span style='color:#111;'> 1.44KB </span>","children":null,"spread":false},{"title":"robots.txt <span style='color:#111;'> 202B </span>","children":null,"spread":false},{"title":"422.html <span style='color:#111;'> 1.51KB </span>","children":null,"spread":false},{"title":"favicon.ico <span style='color:#111;'> 0B </span>","children":null,"spread":false},{"title":"404.html <span style='color:#111;'> 1.53KB </span>","children":null,"spread":false}],"spread":true},{"title":"config.ru <span style='color:#111;'> 153B </span>","children":null,"spread":false},{"title":"db","children":[{"title":"seeds.rb <span style='color:#111;'> 343B </span>","children":null,"spread":false}],"spread":true},{"title":"lib","children":[{"title":"tasks","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":true},{"title":"assets","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":true}],"spread":true},{"title":"Gemfile <span style='color:#111;'> 1.42KB </span>","children":null,"spread":false},{"title":"README.rdoc <span style='color:#111;'> 478B </span>","children":null,"spread":false},{"title":"Rakefile <span style='color:#111;'> 249B </span>","children":null,"spread":false},{"title":"config","children":[{"title":"initializers","children":[{"title":"wrap_parameters.rb <span style='color:#111;'> 372B </span>","children":null,"spread":false},{"title":"inflections.rb <span style='color:#111;'> 647B </span>","children":null,"spread":false},{"title":"cookies_serializer.rb <span style='color:#111;'> 129B </span>","children":null,"spread":false},{"title":"session_store.rb <span style='color:#111;'> 135B </span>","children":null,"spread":false},{"title":"to_time_preserves_timezone.rb <span style='color:#111;'> 500B </span>","children":null,"spread":false},{"title":"filter_parameter_logging.rb <span style='color:#111;'> 194B </span>","children":null,"spread":false},{"title":"mime_types.rb <span style='color:#111;'> 156B </span>","children":null,"spread":false},{"title":"backtrace_silencers.rb <span style='color:#111;'> 404B </span>","children":null,"spread":false},{"title":"assets.rb <span style='color:#111;'> 486B </span>","children":null,"spread":false}],"spread":true},{"title":"application.rb <span style='color:#111;'> 1.23KB </span>","children":null,"spread":false},{"title":"environments","children":[{"title":"test.rb <span style='color:#111;'> 1.71KB </span>","children":null,"spread":false},{"title":"development.rb <span style='color:#111;'> 1.45KB </span>","children":null,"spread":false},{"title":"production.rb <span style='color:#111;'> 3.13KB </span>","children":null,"spread":false}],"spread":false},{"title":"locales","children":[{"title":"en.yml <span style='color:#111;'> 634B </span>","children":null,"spread":false}],"spread":false},{"title":"boot.rb <span style='color:#111;'> 132B </span>","children":null,"spread":false},{"title":"secrets.yml <span style='color:#111;'> 964B </span>","children":null,"spread":false},{"title":"routes.rb <span style='color:#111;'> 1.60KB </span>","children":null,"spread":false},{"title":"environment.rb <span style='color:#111;'> 150B </span>","children":null,"spread":false}],"spread":true},{"title":"test","children":[{"title":"test_helper.rb <span style='color:#111;'> 212B </span>","children":null,"spread":false},{"title":"integration","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false},{"title":"models","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false},{"title":"controllers","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false},{"title":"main_controller_test.rb <span style='color:#111;'> 239B </span>","children":null,"spread":false}],"spread":false},{"title":"fixtures","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false},{"title":"helpers","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false},{"title":"mailers","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false}],"spread":true},{"title":"Gemfile.lock <span style='color:#111;'> 4.16KB </span>","children":null,"spread":false},{"title":".gitignore <span style='color:#111;'> 399B </span>","children":null,"spread":false},{"title":"app","children":[{"title":"views","children":[{"title":"layouts","children":[{"title":"application.html.erb <span style='color:#111;'> 293B </span>","children":null,"spread":false}],"spread":false},{"title":"main","children":[{"title":"show.html.erb <span style='color:#111;'> 66B </span>","children":null,"spread":false},{"title":"_partialtest.html.erb <span style='color:#111;'> 12B </span>","children":null,"spread":false},{"title":"index.html.erb <span style='color:#111;'> 121B </span>","children":null,"spread":false}],"spread":false}],"spread":false},{"title":"models","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false},{"title":"concerns","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false}],"spread":false},{"title":"controllers","children":[{"title":"application_controller.rb <span style='color:#111;'> 204B </span>","children":null,"spread":false},{"title":"concerns","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false},{"title":"main_controller.rb <span style='color:#111;'> 85B </span>","children":null,"spread":false}],"spread":false},{"title":"helpers","children":[{"title":"application_helper.rb <span style='color:#111;'> 29B </span>","children":null,"spread":false},{"title":"main_helper.rb <span style='color:#111;'> 22B </span>","children":null,"spread":false}],"spread":false},{"title":"mailers","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false},{"title":"assets","children":[{"title":"images","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false},{"title":"stylesheets","children":[{"title":"main.scss <span style='color:#111;'> 175B </span>","children":null,"spread":false},{"title":"application.css <span style='color:#111;'> 686B </span>","children":null,"spread":false}],"spread":false},{"title":"javascripts","children":[{"title":"application.js <span style='color:#111;'> 661B </span>","children":null,"spread":false},{"title":"main.coffee <span style='color:#111;'> 211B </span>","children":null,"spread":false}],"spread":false}],"spread":false}],"spread":false},{"title":"bin","children":[{"title":"setup <span style='color:#111;'> 805B </span>","children":null,"spread":false},{"title":"bundle <span style='color:#111;'> 129B </span>","children":null,"spread":false},{"title":"rake <span style='color:#111;'> 213B </span>","children":null,"spread":false},{"title":"rails <span style='color:#111;'> 268B </span>","children":null,"spread":false},{"title":"spring <span style='color:#111;'> 507B </span>","children":null,"spread":false}],"spread":false},{"title":"vendor","children":[{"title":"assets","children":[{"title":"stylesheets","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false},{"title":"javascripts","children":[{"title":".keep <span style='color:#111;'> 0B </span>","children":null,"spread":false}],"spread":false}],"spread":false}],"spread":false}],"spread":false},{"title":"metasploit.rb <span style='color:#111;'> 0B </span>","children":null,"spread":false},{"title":"exploit.rb <span style='color:#111;'> 859B </span>","children":null,"spread":false}],"spread":true}],"spread":true}]

评论信息

免责申明

【只为小站】的资源来自网友分享,仅供学习研究,请务必在下载后24小时内给予删除,不得用于其他任何用途,否则后果自负。基于互联网的特殊性,【只为小站】 无法对用户传输的作品、信息、内容的权属或合法性、合规性、真实性、科学性、完整权、有效性等进行实质审查;无论 【只为小站】 经营者是否已进行审查,用户均应自行承担因其传输的作品、信息、内容而可能或已经产生的侵权或权属纠纷等法律责任。
本站所有资源不代表本站的观点或立场,基于网友分享,根据中国法律《信息网络传播权保护条例》第二十二条之规定,若资源存在侵权或相关问题请联系本站客服人员,zhiweidada#qq.com,请把#换成@,本站将给予最大的支持与配合,做到及时反馈和处理。关于更多版权及免责申明参见 版权及免责申明