7.5

CVE-2013-1756

The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mark EvansDragonfly Gem Version0.9.10
Mark EvansDragonfly Gem Version0.9.11
Mark EvansDragonfly Gem Version0.9.12
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.71% 0.883
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://secunia.com/advisories/52380
http://www.securityfocus.com/bid/58225
https://exchange.xforce.ibmcloud.com/vulnerabilities/82476
https://github.com/markevans/dragonfly/commit/a8775aacf9e5c81cf11bec34b7afa7f27ddfe277
Vendor Advisory
https://groups.google.com/forum/?fromgroups=#%21topic/dragonfly-users/3c3WIU3VQTo