← Back

David Hansson

david_hansson

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Ruby On Rails
ruby_on_rails

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1David Hansson
1Ruby On Rails
Apr 23, 2026
Oct 19, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions."
1David Hansson
1Ruby On Rails
Apr 23, 2026
Oct 19, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, w...Show more
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses XmlSimple (XML::Simple) unsafely, as demonstrated by reading passwords from the Pidgin (Gaim) .purple/accounts.xml file.Show less