
Rails-doubletap-RCE
RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

Exploits Ruby on Rails Action Pack remote code execution (CVE-2016-2098) by abusing unrestricted render() to run arbitrary shell commands through a…

Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python

Rails Asset Pipeline Directory Traversal Vulnerability

short view of ruby on rails properties misconfiguration

Revotech I6032W-FHW IP camera firmware fails to validate authentication fields in API requests, allowing attackers to bypass authentication and…

Proof-of-concept application to verify CVE-2019-5418 path traversal vulnerability in Rails 3, enabling security testing and validation of the exploit.

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…

OpenCATS <= 0.9.4 RCE (CVE-2021-41560)

Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit

This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data

BookingPress < 1.0.11 - Unauthenticated SQL Injection


A vulnerable version of Rails that follows the OWASP Top 10

Ruby on Rails test case demonstrating CVE-2019-5418 file content disclosure via path traversal in Accept header, with PoC and reproduction steps.

Demonstration of CVE-2020-8165 Rails deserialization RCE exploit with realistic Shouter app, payload generation in Ruby, and Redis cache poisoning.

Docker-based sandbox to reproduce and test CVE-2019-5418 Ruby on Rails path traversal vulnerability via crafted Accept headers.

Silly Rails App to demonstrate vuln CVE-2013-0156