Security Advisory
CVE-2013-2105
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html.