Link Details

Link 2001 thumbnail
User 133619 avatar

By murban
via weblog.rubyonrails.org
Published: Aug 11 2006 / 14:18

Due do the fact that several other Web sites have already let the cat out of the bag (and probably also because of the amount of criticism the Rails core team has been getting because of their security by obscurity approach to handling this), an official full disclosure of the problem has been posted on the Rails weblog. As other sites had reported, it is an arbitrary code execution bug that allows the execution of arbitrary ruby code.
  • 7
  • 0
  • 551
  • 186

Comments

Add your comment
User 190346 avatar

ilazarte replied ago:

0 votes Vote down Vote up Reply

I have to shake my head at his comments towards "Commercial User". "If you don't use your real name, you're a troll." What kind of attitude is that towards a user with serious concerns about the platform he's on? It'd be one thing if the commentary wasn't constructive, or genuinely concerned.

I wonder if he's done "calling bullshit on the enterprise astronauts" now...

Add your comment


Html tags not supported. Reply is editable for 5 minutes. Use [code lang="java|ruby|sql|css|xml"][/code] to post code snippets.

Voters For This Link (7)



Voters Against This Link (0)