[Japanese] | |
JVNDB-2006-000853 | |
tDiary arbitrary Ruby script execution vulnerability | |
Overview | |
tDiary is weblog software maintained by the tDiary development project. | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 5.1 (Medium) [IPA Score]
| |
Affected Products | |
| |
tDiary development project | |
| |
Impact | |
Depending on tDiary's configuration, an arbitrary Ruby script could be executed on the web server with tDiary's execution privilege. This could lead to information leak or erasure, password compromise, and contents alteration, etc. | |
Solution | |
| |
Vendor Information | |
tDiary development project | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2006/12/28 |
Date First Published | 2008/05/21 |
Date Last Updated | 2008/05/21 |