Loading vulnerability details…
CVSS v3.1
N/A
EPSS
0.36%
Published
Oct 20, 2004
Modified
Jun 16, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.
Affected Products (2)
References (12)