Rubyonrails

Ruby On Rails

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.77%
  • Veröffentlicht 19.03.2013 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of ...

  • EPSS 0.54%
  • Veröffentlicht 19.03.2013 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) character...

  • EPSS 1.8%
  • Veröffentlicht 19.03.2013 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input ...

  • EPSS 7.16%
  • Veröffentlicht 13.02.2013 01:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

  • EPSS 91.19%
  • Veröffentlicht 30.01.2013 12:00:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct S...

  • EPSS 92.04%
  • Veröffentlicht 13.01.2013 22:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection...

  • EPSS 18.17%
  • Veröffentlicht 13.01.2013 22:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass inte...

Exploit
  • EPSS 2.21%
  • Veröffentlicht 04.01.2013 04:46:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior o...

  • EPSS 0.33%
  • Veröffentlicht 10.08.2012 10:34:47
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web scri...

  • EPSS 0.33%
  • Veröffentlicht 10.08.2012 10:34:47
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HT...