Web Hack List

Collected research

File Name Enumeration in Rails

HackerOne disclosed on HackerOne: File Name Enumeration

A path traversal in the way Rails served static assets: a URL of the form //%5C../%5C../etc/passwd, using percent-encoded backslashes, escaped the document root. Existing and non-existing paths produced different responses, letting an attacker enumerate arbitrary server-side filenames. Fixed in a Rails security release after this report.

Record

Document
HackerOne disclosed on HackerOne: File Name Enumeration
Published by
HackerOne
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of HackerOne, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .