Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-7248

EPSS 11.41% · P94
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-7248

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Ruby on Rails 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Ruby on Rails是美国Rails团队的一套基于Ruby语言的开源Web应用框架。 Ruby on Rails 2.1.3之前的2.1.x版本和2.2.2 之前的2.2.x版本存在输入验证错误漏洞,该漏洞源于不验证具有某些内容类型的请求的令牌,这允许远程攻击者绕过跨站点请求伪造 (CSRF) 保护。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-7248

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-7248

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-12-16 · 23 CVEs total

CVE-2009-4334IBM DB2 Self Tuning Memory Manager (STMM)组件STMM日志文件拒绝服务漏洞
CVE-2009-4305Moodle SCORM模块处理AICC CRS文件SQL注入漏洞
CVE-2009-4304Moodle 'config.php'随机密码暴力破解漏洞
CVE-2009-4303Moodle 储存stores敏感信息泄露漏洞
CVE-2009-4302Moodle 'index_form.html'cleartext安全权限漏洞
CVE-2009-4301Moodle 'mnet/lib.php 'MNET函数文件执行漏洞
CVE-2009-4300Moodle 多个未明验证插件漏洞
CVE-2009-4299Moodle 'showentry.php '未明安全权限漏洞
CVE-2009-4298Moodle LAMS模块未明信息泄露漏洞
CVE-2009-4297Moodle 多个未明跨站请求伪造漏洞
CVE-2009-4335IBM DB2 未明远程漏洞
CVE-2009-4138Linux Kernel 'drivers/firewire/ohci.c'空值废除拒绝服务漏洞
CVE-2009-4333IBM DB2关联数据服务组件信息泄露漏洞
CVE-2009-4332IBM DB2 Problem Determination组件的db2pd拒绝服务漏洞
CVE-2009-4331IBM DB2安装组件权限许可和访问控制漏洞
CVE-2009-4330IBM DB2 Engine Utilities组件db2licm未明漏洞
CVE-2009-4329IBM DB2 Engine Utilities组件db2ra数据拒绝服务漏洞
CVE-2009-4328IBM DB2 DRDA服务组件未明拒绝服务漏洞
CVE-2009-4327IBM DB2 基础设施组件内存池大小拒绝服务漏洞
CVE-2009-4326IBM DB2 基础设施组件RAND函数信息泄露漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-7248

No comments yet


Leave a comment