David Hansson

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 2
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2007-5379

    Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses XmlSimple (XML::Simple) unsafely, as demonstrated by reading passwords from the Pidgin (Gaim) .purple/accounts.xml file.

    Last Modified: Apr 23, 2026
    Published: Oct 19, 2007

    CVE-2007-5380

    Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions."

    Last Modified: Apr 23, 2026
    Published: Oct 19, 2007
    Items Per Page
    David_Hansson Vulnerabilities & Security CVEs | CVE-DB