CVE-2013-2512: Ftpd Project Ftpd

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument within FTP protocol traffic.

Affected products

Published 2021-01-26. Last modified 2026-06-16.