CVE-2013-1875
command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename.
Date published : 2013-03-20
http://seclists.org/fulldisclosure/2013/Mar/175
http://packetstormsecurity.com/files/120847/Ruby-Gem-Command-Wrap-Command-Execution.html