lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
References
Link | Resource |
---|---|
http://vapid.dhs.org/advisories/sounder-ruby-gem-cmd-inj.html | Exploit |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2013-08-29 05:07
Updated : 2013-08-29 15:03
NVD link : CVE-2013-5647
Mitre link : CVE-2013-5647
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
adam_zaninovich
- sounder
ruby-lang
- ruby