CVE-2013-1898 Information

Description

lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

Reference

http://osvdb.org/91839 http://seclists.org/fulldisclosure/2013/Mar/218 http://vapid.dhs.org/advisories/thumbshooter-ruby-gem-remoteexec.html http://www.openwall.com/lists/oss-security/2013/03/26/13 http://www.openwall.com/lists/oss-security/2013/03/26/3

Share on: