Description
lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Published: 2013-04-09
Score: 7.5 High
EPSS: 2.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-0187 lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
Github GHSA Github GHSA GHSA-7fqj-cg79-f2pv Thumbshooter vulnerable to Code Injection
History

No history.

Subscriptions

Digineo Thumbshooter
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-09-16T21:03:22.237Z

Reserved: 2013-02-19T00:00:00.000Z

Link: CVE-2013-1898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-04-09T20:55:02.007

Modified: 2026-06-16T23:52:20.973

Link: CVE-2013-1898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')