CVE-2012-3463
- EPSS 0.33%
- Published 10.08.2012 10:34:47
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the pr...
- EPSS 0.98%
- Published 08.08.2012 10:26:19
- Last modified 11.04.2025 00:51:21
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attac...
CVE-2012-2695
- EPSS 0.64%
- Published 22.06.2012 14:55:01
- Last modified 11.04.2025 00:51:21
The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certai...
CVE-2012-2694
- EPSS 0.19%
- Published 22.06.2012 14:55:01
- Last modified 11.04.2025 00:51:21
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which a...
- EPSS 2.51%
- Published 22.06.2012 14:55:01
- Last modified 11.04.2025 00:51:21
The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct ...
CVE-2012-2660
- EPSS 0.35%
- Published 22.06.2012 14:55:01
- Last modified 11.04.2025 00:51:21
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which a...
CVE-2012-1099
- EPSS 0.4%
- Published 13.03.2012 10:55:01
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary we...
CVE-2012-1098
- EPSS 0.38%
- Published 13.03.2012 10:55:01
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated thr...
CVE-2011-4319
- EPSS 0.61%
- Published 28.11.2011 11:55:09
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HT...
CVE-2011-2932
- EPSS 0.81%
- Published 29.08.2011 18:55:01
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script o...