
CVE-2013-1756
https://notcve.org/view.php?id=CVE-2013-1756
09 Jun 2014 — The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request. La gema Dragonfly 0.7 anterior a 0.8.6 y 0.9.x anterior a 0.9.13 para Ruby, cuando se utiliza con Ruby on Rails, permite a atacantes remotos ejecutar código arbitrario a través de una solicitud manipulada. • http://secunia.com/advisories/52380 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2013-5671 – Fog Dragonfly 0.8.2 Command Injection
https://notcve.org/view.php?id=CVE-2013-5671
03 Sep 2013 — lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors. lib/dragonfly/imagemagickutils.rb en la gema fog-dragonfly 0.8.2 para Ruby permite a atacantes remotos ejecutar comandos arbitrarios a través de vectores no especificados. Ruby Gem Fog Dragonfly version 0.8.2 suffers from a remote command injection vulnerability. • http://seclists.org/fulldisclosure/2013/Sep/18 •