Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-1098

Опубликовано: 13 мар. 2012
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-actionpack-2.3fixed2.3.14-3package
railsfixed2.3.14package
railsnot-affectedsqueezepackage

Примечания

  • (code lives within ruby-actionpack in unstable)

EPSS

Процентиль: 59%
0.00377
Низкий

Связанные уязвимости

ubuntu
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.

redhat
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.

nvd
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.

github
больше 8 лет назад

activesupport Cross-site Scripting vulnerability

EPSS

Процентиль: 59%
0.00377
Низкий