CVE-2013-6421
The unpack_zip function in archive_unpacker.rb in the sprout gem 0.7.246 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a (1) filename or (2) path.
Date published : 2013-12-12
http://archives.neohapsis.com/archives/bugtraq/2013-12/0077.html
http://vapid.dhs.org/advisories/sprout-0.7.246-command-inj.html