Description
lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
References (1)
Core 1
Core References
Exploit x_refsource_misc
http://vapid.dhs.org/advisories/sounder-ruby-gem-cmd-inj.html
Scores
EPSS
0.0272
EPSS Percentile
86.1%
Details
CWE
CWE-94
Status
published
Products (2)
adam_zaninovich/sounder
1.0.1
rubygems/sounder
0 - 1.0.2RubyGems
Published
Aug 29, 2013
Tracked Since
Feb 18, 2026