Description
Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831.
Remediation
References
Related Vulnerabilities
Python Cryptographic Issues Vulnerability (CVE-2013-7040)
WordPress Plugin eCommerce Product Catalog for WordPress Cross-Site Request Forgery (2.9.43)
MySQL CVE-2019-2946 Vulnerability (CVE-2019-2946)
WordPress Plugin Request a Quote Cross-Site Scripting (2.0.0)
WordPress 4.3.x Denial of Service Vulnerability (4.3 - 4.3.15)