VYPR
High severityNVD Advisory· Published Aug 14, 2006· Updated Apr 16, 2026

CVE-2006-4112

CVE-2006-4112

Description

Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
railsRubyGems
>= 1.1.0, < 1.1.61.1.6

Affected products

5
  • Rubyonrails/Rails5 versions
    cpe:2.3:a:rubyonrails:rails:1.1.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:rubyonrails:rails:1.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:1.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:1.1.4:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

17

News mentions

0

No linked articles in our index yet.