Vulnerabilities > CVE-2014-2888 - Unspecified vulnerability in Herry Sfpagent

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

lib/sfpagent/bsig.rb in the sfpagent gem before 0.4.15 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the module name in a JSON request.

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/126223/rubysfpagent-exec.txt
idPACKETSTORM:126223
last seen2016-12-05
published2014-04-18
reporterLarry W. Cashdollar
sourcehttps://packetstormsecurity.com/files/126223/Ruby-Gem-sfpagent-0.4.14-Command-Injection.html
titleRuby Gem sfpagent 0.4.14 Command Injection