RubyGems mail Directory Traversal and Command Injection Vulnerabilities
17 May. 2012
Summary
RubyGems mail is prone to a directory-traversal vulnerability and multiple command-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Credit:
The information has been provided by The vendor has reported these issues..
The original article can be found at: http://www.securityfocus.com/bid/53257
Remote attackers can use a specially crafted request with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application. Also, attackers can execute arbitrary commands with the privileges of the user running the application.
Vendor Status:
Vendor had issued an update for this vulnerability