ID:6396 - Exploit for Command injection in Ruby - CVE-2017-17405

 
Main Vulnerability Database Exploits ID:6396 - Exploit for Command injection in Ruby - CVE-2017-17405

ID:6396 - Exploit for Command injection in Ruby - CVE-2017-17405

Published: June 17, 2021


Vulnerability identifier: #VU9718
Vulnerability risk: High
CVE-ID: CVE-2017-17405
CWE-ID: CWE-77
Exploitation vector: Remote access
Vulnerable software:
Ruby

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The weakness exists due to flaws in the Net::FTP. A remote attacker can inject and execute arbitrary commands with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

Remediation

Update to version 2.2.9, 2.3.6, 2.4.3 or later.