CVE-2013-1875 Information

Description

command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename.

Reference

http://packetstormsecurity.com/files/120847/Ruby-Gem-Command-Wrap-Command-Execution.html http://seclists.org/fulldisclosure/2013/Mar/175 http://www.openwall.com/lists/oss-security/2013/03/19/9 http://www.osvdb.org/91450

Share on: