Описание
lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Дополнительная информация
Статус:
Critical
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=924240rubygem-curl: insufficient URL escaping command injection
7.5 High
CVSS2
Связанные уязвимости
nvd
почти 13 лет назад
lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
7.5 High
CVSS2