RubySec

Providing security resources for the Ruby community

OSVDB-73751 (spree): Spree Content Controller Unspecified Arbitrary File Disclosure

Spree Content Controller Unspecified Arbitrary File Disclosure

Published: April 19, 2011

SECURITY IDENTIFIERS

GEM

spree

PATCHED VERSIONS

>= 0.50.1

DESCRIPTION

Spree Gem for Ruby would allow a user to request a specially crafted URL and expose arbitrary files on the server

RELATED