Podatność CVE-2013-2513


Publikacja: 2023-12-12   Modyfikacja: 2023-12-14

Opis:
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.

Typ:

CWE-77

(Improper Neutralization of Special Elements used in a Command ('Command Injection'))

Affected software
Milboj -> Flash tool 

 Referencje:
https://github.com/advisories/GHSA-6325-6g32-7p35
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/flash_tool/CVE-2013-2513.yml

Copyright 2024, cxsecurity.com

 

Back to Top