CVE-2013-1898: Digineo Thumbshooter

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

Affected products

  • Digineo Thumbshooter: version 0.1.5 only

Published 2013-04-09. Last modified 2026-06-16.