Ruby on Rails String Interpolation led to Remote Code Execution
13-Mar-2017 3629
@nahamsec and I discovered a Cross-Site Scripting vulnerability a few months ago related to Rails typecasting request variables into JSON. This caused the output to be JSON formatted and the JSON indexes would avoid XSS encoding. We decided to run with this concept and explore the rest of the website to see if we could identify other vulnerabilities using the same method.
Ruby on Rails String Interpolation led to Remote Code Execution #ruby #rubydeveloper #rubyonrails #Ruby #on #Rails #String #Interpolation #led #to #Remote #Code #Execution #code https://rubyonrails.ba/link/ruby-on-rails-string-interpolation-led-to-remote-code-execution