CVE-2014-4996: Vladtheenterprising Project Vladtheenterprising
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.#{target_host}.
Affected products
- Vladtheenterprising Project Vladtheenterprising: version 0.2.0 only
Published 2018-01-10. Last modified 2026-06-17.