Details
Alert ID 100029
Alert Type Script Active
Status alpha
Risk High
CWE 74
WASC 33
Technologies Targeted All
Tags CWE-74
OWASP_2017_A01
OWASP_2021_A03
WSTG-V42-ATHZ-01
More Info Scan Rule Help

Summary

The application seems to be subject to CVE-2019-5418. By sending a specially crafted request it was possible to have the target return data from the server file system.

Solution

Upgrade to a version of Ruby/Rails where this issue is fixed. (See references for further details).

Other Info

References

Code

active/cve-2019-5418.js