CVE-2016-2098
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by...
- Published
- Apr 7, 2016
- Updated
- Aug 5, 2024
- Assigning CNA
- redhat
- Evidence observed
- Jul 11, 2016
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:PHigh · next 30 days
- Percentile
- 99.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
Sources
13- CVE-2016-2098Exploit
Exploits Ruby on Rails Action Pack remote code execution (CVE-2016-2098) by abusing unrestricted render() to run arbitrary shell commands through a vulnerable parameter.
Proof-of-concept exploit for CVE-2016-2098, demonstrating remote Ruby code execution through Rails render method abuse; intended for security testing and education.
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.