7.5
CVSSv2

CVE-2011-5330

Published: 18/11/2019 Updated: 22/11/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

distributed ruby project distributed ruby 1.8

Github Repositories

Distributed Ruby - Send instance_eval/syscall Code Execution - Ruby script

drbpwn Description CVE-2011-5330 exploit in ruby This Ruby script provides a workaround for exploiting Distributed Ruby (DRb) vulnerabilities using instance_eval and syscall methods It aims to serve as an alternative to the missing Metasploit module for DRb exploitation While the Metasploit module might reappear in future versions, this script can be utilized in the meantime