CVE-2016-2098
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
- Affected products
- Ruby On Rails, Suse
- Debian Debian Linux
- = 8.0
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- CVSS 3.1
- 7.3 HIGH
- EPSS
- 85.0% (100th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2016-04-07
CVE-2016-2098 at NVD
18 known exploits for CVE-2016-2098
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2016-2098
CVE-2016-2098
CVE-2016-2098
CVE-2016-2098-my-first-exploit
PoC_CVE-2016-2098_Rails42
Ruby-on-Rails-ActionPack-Inline-ERB-Remote-Code-Execution
CVE-2016-2098-PoC
CVE-2016-2098
rails-PoC-CVE-2016-2098
CVE-2016-2098
CVE-2016-2098
Exploit for Improper Input Validation in Debian Debian_Linux
Ruby on Rails ActionPack Inline ERB - Code Execution (Metasploit)
Ruby on Rails ActionPack Inline ERB - Code Execution (Metasploit)
Ruby On Rails ActionPack Inline ERB Code Execution
Immunity Canvas: RAILS_ACTIONPACK_RENDER
Ruby on Rails Action Pack远程代码执行漏洞
Ruby on Rails ActionPack Inline ERB Code Execution