Description
Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831.
Remediation
References
Related Vulnerabilities
WordPress Plugin Get URL Cron Multiple Vulnerabilities (1.4.7)
Internet Information Services Other Vulnerability (CVE-2000-0126)
WordPress Plugin All-in-One WP Migration Arbitrary File Upload (7.40)
MySQL CVE-2013-3798 Vulnerability (CVE-2013-3798)
WordPress Plugin Gravity Forms Cross-Site Scripting (1.9.15.11)