CVE-2012-3463
- EPSS 0.33%
- Veröffentlicht 10.08.2012 10:34:47
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the pr...
- EPSS 0.98%
- Veröffentlicht 08.08.2012 10:26:19
- Zuletzt bearbeitet 11.04.2025 00:51:21
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attac...
CVE-2012-2695
- EPSS 0.64%
- Veröffentlicht 22.06.2012 14:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certai...
CVE-2012-2694
- EPSS 0.19%
- Veröffentlicht 22.06.2012 14:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which a...
- EPSS 2.51%
- Veröffentlicht 22.06.2012 14:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct ...
CVE-2012-2660
- EPSS 0.35%
- Veröffentlicht 22.06.2012 14:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which a...
CVE-2012-1099
- EPSS 0.4%
- Veröffentlicht 13.03.2012 10:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary we...
CVE-2012-1098
- EPSS 0.38%
- Veröffentlicht 13.03.2012 10:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated thr...
CVE-2011-4319
- EPSS 0.61%
- Veröffentlicht 28.11.2011 11:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HT...
CVE-2011-2932
- EPSS 0.81%
- Veröffentlicht 29.08.2011 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script o...