{"id":"GHSA-wwmf-6p58-6vj2","summary":"Remote code execution in rwiki","details":"The editing form in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to execute arbitrary Ruby code via unknown attack vectors.","aliases":["CVE-2006-2582"],"modified":"2025-04-03T14:25:17Z","published":"2017-10-24T18:33:38Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T22:01:28Z","nvd_published_at":"2006-05-25T10:02:00Z","cwe_ids":[]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2582"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26668"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wwmf-6p58-6vj2"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rwiki/CVE-2006-2582.yml"},{"type":"WEB","url":"https://web.archive.org/web/20090501134922/http://www2a.biglobe.ne.jp/~seki/ruby/rwiki.html"},{"type":"WEB","url":"http://secunia.com/advisories/20264"},{"type":"WEB","url":"http://www.vupen.com/english/advisories/2006/1949"}],"affected":[{"package":{"name":"rwiki","ecosystem":"RubyGems","purl":"pkg:gem/rwiki"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0pre1"},{"fixed":"2.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-wwmf-6p58-6vj2/GHSA-wwmf-6p58-6vj2.json"}}],"schema_version":"1.9.0"}