{"id":"CVE-2013-1756","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-1756","summary":"The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.","details":"The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.","published":"2014-06-09T19:55:06.663","modified":"2026-06-16T23:52:03.787","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/markevans/dragonfly/commit/a8775aacf9e5c81cf11bec34b7afa7f27ddfe277","label":"markevans/dragonfly@a8775aa"},"references":[{"type":"WEB","url":"http://secunia.com/advisories/52380"},{"type":"WEB","url":"http://www.securityfocus.com/bid/58225"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/82476"},{"type":"ADVISORY","url":"https://github.com/markevans/dragonfly/commit/a8775aacf9e5c81cf11bec34b7afa7f27ddfe277"},{"type":"WEB","url":"https://groups.google.com/forum/?fromgroups=#%21topic/dragonfly-users/3c3WIU3VQTo"},{"type":"WEB","url":"http://secunia.com/advisories/52380"},{"type":"WEB","url":"http://www.securityfocus.com/bid/58225"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/82476"},{"type":"ADVISORY","url":"https://github.com/markevans/dragonfly/commit/a8775aacf9e5c81cf11bec34b7afa7f27ddfe277"},{"type":"WEB","url":"https://groups.google.com/forum/?fromgroups=#%21topic/dragonfly-users/3c3WIU3VQTo"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:52:03.787"}}