Main
Vulnerability Database
Exploits
ID:6396 - Exploit for Command injection in Ruby - CVE-2017-17405
ID:6396 - Exploit for Command injection in Ruby - CVE-2017-17405
Published: June 17, 2021
Vulnerability identifier: #VU9718
Vulnerability risk: High
CVE-ID: CVE-2017-17405
CWE-ID: CWE-77
Exploitation vector: Remote access
Vulnerable software:
Ruby
Ruby
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The weakness exists due to flaws in the Net::FTP. A remote attacker can inject and execute arbitrary commands with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to flaws in the Net::FTP. A remote attacker can inject and execute arbitrary commands with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Remediation
Update to version 2.2.9, 2.3.6, 2.4.3 or later.