The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2013/05/18/4 | mailing list exploit |
http://vapid.dhs.org/advisories/show_in_browser.html | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/84378 | vdb entry |