Rubyonrails

Ruby On Rails

49 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Published 08.11.2014 11:55:02
  • Last modified 12.04.2025 10:46:40

Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, al...

  • EPSS 1.44%
  • Published 07.07.2014 11:01:30
  • Last modified 12.04.2025 10:46:40

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands b...

  • EPSS 6.46%
  • Published 20.02.2014 15:27:09
  • Last modified 11.04.2025 00:51:21

actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memor...

  • EPSS 0.89%
  • Published 20.02.2014 15:27:09
  • Last modified 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML ...

  • EPSS 0.51%
  • Published 07.12.2013 00:55:03
  • Last modified 11.04.2025 00:51:21

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attac...

  • EPSS 1.51%
  • Published 07.12.2013 00:55:03
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via th...

  • EPSS 70.84%
  • Published 07.12.2013 00:55:03
  • Last modified 11.04.2025 00:51:21

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to e...

  • EPSS 0.71%
  • Published 07.12.2013 00:55:03
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script ...

Exploit
  • EPSS 0.48%
  • Published 22.04.2013 03:27:13
  • Last modified 11.04.2025 00:51:21

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote ...

  • EPSS 0.63%
  • Published 19.03.2013 22:55:01
  • Last modified 11.04.2025 00:51:21

The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characte...