By murban
via weblog.rubyonrails.org
Published: Aug 11 2006 / 14:18
Due do the fact that several other Web sites have already let the cat out of the bag (and probably also because of the amount of criticism the Rails core team has been getting because of their security by obscurity approach to handling this), an official full disclosure of the problem has been posted on the Rails weblog. As other sites had reported, it is an arbitrary code execution bug that allows the execution of arbitrary ruby code.
Comments
ilazarte replied ago:
I have to shake my head at his comments towards "Commercial User". "If you don't use your real name, you're a troll." What kind of attitude is that towards a user with serious concerns about the platform he's on? It'd be one thing if the commentary wasn't constructive, or genuinely concerned.
I wonder if he's done "calling bullshit on the enterprise astronauts" now...
Voters For This Link (7)
Voters Against This Link (0)