Rubyonrails

Rails

111 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.63%
  • Published 19.03.2013 22:55:01
  • Last modified 11.04.2025 00:51:21

The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characte...

  • EPSS 1.44%
  • Published 13.02.2013 01:55:05
  • Last modified 11.04.2025 00:51:21

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

  • EPSS 7.16%
  • Published 13.02.2013 01:55:05
  • Last modified 11.04.2025 00:51:21

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

  • EPSS 91.19%
  • Published 30.01.2013 12:00:08
  • Last modified 11.04.2025 00:51:21

lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct S...

  • EPSS 18.17%
  • Published 13.01.2013 22:55:00
  • Last modified 11.04.2025 00:51:21

Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass inte...

  • EPSS 92.04%
  • Published 13.01.2013 22:55:00
  • Last modified 11.04.2025 00:51:21

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection...

Exploit
  • EPSS 2.21%
  • Published 04.01.2013 04:46:02
  • Last modified 11.04.2025 00:51:21

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior o...

Exploit
  • EPSS 0.4%
  • Published 04.01.2013 04:46:02
  • Last modified 11.04.2025 00:51:21

The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environ...

  • EPSS 0.33%
  • Published 10.08.2012 10:34:47
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the pr...

  • EPSS 0.33%
  • Published 10.08.2012 10:34:47
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HT...