Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-3221

Опубликовано: 22 апр. 2013
Источник: debian
EPSS Низкий

Описание

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rails-3.2unfixedpackage
ruby-activerecord-3.2unfixedpackage
ruby-activerecord-2.3unfixedpackage
ruby-activerecord-2.3end-of-lifewheezypackage
railsfixed2.3.14.1package

Примечания

  • Starting with 2.3.14.1 rails is a transition package

  • This is a general design problem and only mitigated by documented best practices

EPSS

Процентиль: 78%
0.01962
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

redhat
больше 13 лет назад

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

nvd
больше 13 лет назад

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

github
около 4 лет назад

Active Record component in Ruby on Rails has a data-type injection vulnerability

EPSS

Процентиль: 78%
0.01962
Низкий