Rubyonrails

Rails

119 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.74%
  • Veröffentlicht 13.02.2013 01:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

  • EPSS 91.76%
  • Veröffentlicht 30.01.2013 12:00:08
  • Zuletzt bearbeitet 29.04.2026 01:13:23

lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct S...

  • EPSS 18.17%
  • Veröffentlicht 13.01.2013 22:55:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass inte...

  • EPSS 91.91%
  • Veröffentlicht 13.01.2013 22:55:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection...

Exploit
  • EPSS 1.02%
  • Veröffentlicht 04.01.2013 04:46:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior o...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 04.01.2013 04:46:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environ...

  • EPSS 0.33%
  • Veröffentlicht 10.08.2012 10:34:47
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the pr...

  • EPSS 0.25%
  • Veröffentlicht 10.08.2012 10:34:47
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HT...

  • EPSS 0.33%
  • Veröffentlicht 10.08.2012 10:34:47
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web scri...

  • EPSS 0.98%
  • Veröffentlicht 08.08.2012 10:26:19
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attac...