vendor:
WEBrick
by:
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: WEBrick
Affected Version From: Ruby 1.8.6 patchlevel 388, Ruby 1.8.7 patchlevel 249, Ruby 1.9.1 patchlevel 378
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Command Injection Vulnerability in Ruby WEBrick
Ruby WEBrick is prone to a command-injection vulnerability because it fails to adequately sanitize user-supplied input in log files. Attackers can exploit this issue to execute arbitrary commands in a terminal.
Mitigation:
Update to a version of Ruby that has been patched to address this vulnerability. No official patch is available at the moment.