Description
The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin Calendar Event Multi View Security Bypass (1.4.06)
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-15731)
Joomla URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-23798)
WordPress Plugin Email Users Cross-Site Scripting (4.8.2)
WordPress Plugin Instagram Feed Cross-Site Scripting (1.4.6.2)