|
|
| |
|
| |
rubygem-multi_xml: code execution
| Package(s): | rubygem-multi_xml |
CVE #(s): | CVE-2013-0175
|
| Created: | January 25, 2013 |
Updated: | January 30, 2013 |
| Description: |
From the Red Hat bugzilla entry:
A security flaw was found in the way multi_xml gem, a Ruby gem to provide swappable XML backends utilizing LibXML, Nokogiri, Ox, or REXML, performed Symbol and YAML parameters parsing. A remote attacker could use this flaw to execute arbitrary code with the privileges of the Ruby on Rails application using the multi_xml gem via specially-crafted HTTP POST request.
|
| Alerts: |
|
( Log in to post comments)
|
|
|