Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2018-16470
Disclosure Date: November 13, 2018 (last updated November 08, 2023)
There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.
0
Attacker Value
Unknown
CVE-2011-1329
Disclosure Date: May 31, 2011 (last updated October 04, 2023)
WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.
0
Attacker Value
Unknown
CVE-2011-2215
Disclosure Date: May 31, 2011 (last updated October 04, 2023)
Unspecified vulnerability in WalRack 1.x before 1.1.8 and 2.x before 2.0.6 has unknown impact and attack vectors, possibly related to file deletion and an encoded URL, a different vulnerability than CVE-2011-1329.
0