Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-4094

Опубликовано: 30 сент. 2008
Источник: debian
EPSS Низкий

Описание

Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2.1.0-1package

Примечания

  • in mysql this only allows information disclosure as multiline statements are

  • not allowed by default

EPSS

Процентиль: 87%
0.03119
Низкий

Связанные уязвимости

ubuntu
больше 17 лет назад

Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.

nvd
больше 17 лет назад

Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.

github
больше 8 лет назад

Rails ActiveRecord gem vulnerable to SQL injection

EPSS

Процентиль: 87%
0.03119
Низкий