Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-6496

Опубликовано: 04 янв. 2013
Источник: debian
EPSS Низкий

Описание

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-activerecord-3.2fixed3.2.6-3package
ruby-activerecord-2.3fixed2.3.14-3package
railsfixed2.3.14.1package

Примечания

  • Starting with 2.3.14.1 rails is a transition package

EPSS

Процентиль: 84%
0.02213
Низкий

Связанные уязвимости

ubuntu
около 13 лет назад

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

redhat
около 13 лет назад

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

nvd
около 13 лет назад

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

github
больше 8 лет назад

Active Record contains SQL Injection

EPSS

Процентиль: 84%
0.02213
Низкий