RCE (Remote Code Execution) Vulnerability on Ruby

Disclosed: 2017-04-05 08:20:50 By cloudyvirus To ruby
Medium
Vulnerability Details
Hi Ruby, Here is Shaifullah Shaon (Black_EyE), An Ethical Hacker. a white hat cyber security researcher from Bangladesh reporting a serious [3'rd ranking in OWASP] security vulnerability on your system. I faced a technical security bug called RCE (Remote Code Execution) Vulnerability on Ruby. Let's follow me... 1. Find any online execution site for ruby. CZ I didn't enough Speach for install ruby in my HDD. ;p 2. Input this code only. Code: # Hello World Program in Ruby system "clear;ls;uname -a;echo RCE in Ruby Language By Black_EyE"; 3. As you see, Here have RCE using your Language. Please See my Video Poc for understand clearly. Hopefully Those are Very critical issue. Resolve those issue as soon as possible. Here is proof as video concept: https://youtu.be/XTdSzAbNQ9Q Thank you Shaifullah Shaon (Black_EyE) [email protected]
Actions
View on HackerOne
Report Stats
  • Report ID: 218342
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 9
Share this report