Rubyonrails

Rails

111 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.63%
  • Veröffentlicht 19.03.2013 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characte...

  • EPSS 1.44%
  • Veröffentlicht 13.02.2013 01:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

  • EPSS 7.16%
  • Veröffentlicht 13.02.2013 01:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

  • EPSS 91.19%
  • Veröffentlicht 30.01.2013 12:00:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct S...

  • EPSS 18.17%
  • Veröffentlicht 13.01.2013 22:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass inte...

  • EPSS 92.04%
  • Veröffentlicht 13.01.2013 22:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection...

Exploit
  • EPSS 2.21%
  • Veröffentlicht 04.01.2013 04:46:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior o...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 04.01.2013 04:46:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environ...

  • EPSS 0.33%
  • Veröffentlicht 10.08.2012 10:34:47
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the pr...

  • EPSS 0.33%
  • Veröffentlicht 10.08.2012 10:34:47
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HT...