Rubyonrails

Ruby On Rails

49 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.77%
  • Published 19.03.2013 22:55:01
  • Last modified 11.04.2025 00:51:21

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of ...

  • EPSS 0.54%
  • Published 19.03.2013 22:55:01
  • Last modified 11.04.2025 00:51:21

The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) character...

  • EPSS 1.8%
  • Published 19.03.2013 22:55:01
  • Last modified 11.04.2025 00:51:21

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input ...

  • EPSS 7.16%
  • Published 13.02.2013 01:55:05
  • Last modified 11.04.2025 00:51:21

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

  • EPSS 91.19%
  • Published 30.01.2013 12:00:08
  • Last modified 11.04.2025 00:51:21

lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct S...

  • EPSS 92.04%
  • Published 13.01.2013 22:55:00
  • Last modified 11.04.2025 00:51:21

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection...

  • EPSS 18.17%
  • Published 13.01.2013 22:55:00
  • Last modified 11.04.2025 00:51:21

Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass inte...

Exploit
  • EPSS 2.21%
  • Published 04.01.2013 04:46:02
  • Last modified 11.04.2025 00:51:21

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior o...

  • EPSS 0.33%
  • Published 10.08.2012 10:34:47
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web scri...

  • EPSS 0.33%
  • Published 10.08.2012 10:34:47
  • Last modified 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HT...