So if you don't run CGI nor run a system command within your code, are you fairly safe?
If you do have some gem that runs a system cmd, wouldn't it still require url input to get passed down to that command?
I'm not advocating NOT upgrading your systems, but still fuzzy on the attack vector if this test requires I upload a cgi script