General | |
---|---|
Score: | 5.0/10.0 |
Severity: | Medium |
Category: | Information Leak / Disclosure |
Impact Metrics | |
Confidentiality: | Partial |
Integrity: | None |
Availability: | None |
Exploitability Metrics | |
Access Vector: | Network |
Access Complexity: | Low |
Authentication: | None |

Published on 20/10/07 - Updated on 31/10/12
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses XmlSimple (XML::Simple) unsafely, as demonstrated by reading passwords from the Pidgin (Gaim) .purple/accounts.xml file.
CWE-200 (Information Exposure)
An information exposure is the intentional or unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.
![]() | CVE-2007-5379 |
![]() | 2007/VULN450, 2007/VULN522 |
No exploits available for this CVE in our database.