Vulnerability CVE-2013-2513


Published: 2023-12-12   Modified: 2023-12-14

Description:
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.

Type:

CWE-77

(Improper Neutralization of Special Elements used in a Command ('Command Injection'))

Affected software
Milboj -> Flash tool 

 References:
https://github.com/advisories/GHSA-6325-6g32-7p35
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/flash_tool/CVE-2013-2513.yml

Copyright 2024, cxsecurity.com

 

Back to Top