Security Advisory

CVE-2013-5036

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-05-27 15:00:00
Last updated 2024-08-06 16:59:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb.