7.5
CVE-2011-0448
- EPSS 2.17%
- Veröffentlicht 21.02.2011 18:00:01
- Zuletzt bearbeitet 16.06.2026 23:27:24
- Erkennungen
Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rubyonrails ≫ Rails Version 3.0.0
Rubyonrails ≫ Rails Version 3.0.0 Update beta
Rubyonrails ≫ Rails Version 3.0.0 Update beta2
Rubyonrails ≫ Rails Version 3.0.0 Update beta3
Rubyonrails ≫ Rails Version 3.0.0 Update beta4
Rubyonrails ≫ Rails Version 3.0.0 Update rc
Rubyonrails ≫ Rails Version 3.0.0 Update rc2
Rubyonrails ≫ Rails Version 3.0.1
Rubyonrails ≫ Rails Version 3.0.1 Update pre
Rubyonrails ≫ Rails Version 3.0.2
Rubyonrails ≫ Rails Version 3.0.2 Update pre
Rubyonrails ≫ Rails Version 3.0.3
Rubyonrails ≫ Rails Version 3.0.4 Update rc1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.17% | 0.799 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057650.html
http://www.vupen.com/english/advisories/2011/0877
http://groups.google.com/group/rubyonrails-security/msg/4e19864cf6ad40ad?dmode=source&output=gplain
http://secunia.com/advisories/43278
http://securitytracker.com/id?1025063
http://weblog.rubyonrails.org/2011/2/8/new-releases-2-3-11-and-3-0-4
https://github.com/rails/rails/commit/354da43ab0a10b3b7b3f9cb0619aa562c3be8474