RubySec

Providing security resources for the Ruby community

CVE-2013-2105 (show_in_browser): Show In Browser Gem for Ruby /tmp/browser.html Arbitrary Script Injection

ADVISORIES

GEM

show_in_browser

PATCHED VERSIONS

None.

DESCRIPTION

Show In Browser Gem for Ruby contains a flaw that is triggered when the application does not validate input passed via the /tmp/browser.html file. This may allow a local attacker to create a specially crafted request that would execute arbitrary script code in a user’s browser.