Critical severity9.8NVD Advisory· Published Jan 26, 2021· Updated Jun 16, 2026
CVE-2013-2512
CVE-2013-2512
Description
The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument within FTP protocol traffic.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ftpdRubyGems | < 0.2.2 | 0.2.2 |
Affected products
3- cpe:2.3:a:ftpd_project:ftpd:0.2.1:*:*:*:*:ruby:*:*
- Ruby/ftpd gemdescription
Patches
Vulnerability mechanics
References
6- vapidlabs.com/advisory.phpnvdExploitThird Party Advisory
- github.com/advisories/GHSA-7vxr-6cxg-j3x8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-2512ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/ftpd/CVE-2013-2512.ymlghsaWEB
- github.com/wconrad/ftpd/commit/828064f1a0ab69b2642c59cab8292a67bb44182cghsaWEB
- web.archive.org/web/20210206231123/http://vapidlabs.com/advisory.phpghsaWEB
News mentions
0No linked articles in our index yet.