Sfpagent Ruby Gem Remote Command Injection Vulnerability
BID:66935
Info
Sfpagent Ruby Gem Remote Command Injection Vulnerability
| Bugtraq ID: | 66935 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2888 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2014 12:00AM |
| Updated: | Apr 22 2014 12:41AM |
| Credit: | Larry W. Cashdollar |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Sfpagent Ruby Gem Remote Command Injection Vulnerability
Sfpagent Ruby gem is prone to a remote command-injection vulnerability because it fails to sufficiently sanitize certain unspecified user-supplied data.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in the context of the affected application.
Sfpagent 0.4.14 is vulnerable.
Sfpagent Ruby gem is prone to a remote command-injection vulnerability because it fails to sufficiently sanitize certain unspecified user-supplied data.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in the context of the affected application.
Sfpagent 0.4.14 is vulnerable.
Exploit / POC
Sfpagent Ruby Gem Remote Command Injection Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
Sfpagent Ruby Gem Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Sfpagent Ruby Gem Remote Command Injection Vulnerability
References:
References: