Sploitus

CVE-2016-2098

18 known exploits for CVE-2016-2098

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

Affected products
Ruby On Rails, Suse
Debian Debian Linux
= 8.0
Fix
Available
CVSS 2.0
7.5 HIGH
CVSS 3.1
7.3 HIGH
EPSS
85.0% (100th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2016-04-07
CVE-2016-2098 at NVD
Authoritative description, scoring and affected products

18 known exploits for CVE-2016-2098

Proof-of-concept code and exploit modules indexed by Sploitus