RSS   Vulnerabilities for 'Ruby on ra2000ils'   RSS

2013-01-13
 
CVE-2013-0155

CWE-264
 

 
Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.

 

 >>> Vendor: Rubyonrails 12 Products
Ruby on rails
Rails
Ruby on ra2000ils
Jquery-rails
Jquery-ujs
Web console
Html sanitizer
Active job
Active storage
Actionview
Actionpack page-caching
Active resource


Copyright 2021, cxsecurity.com

 

Back to Top