Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3483

Опубликовано: 07 июл. 2014
Источник: debian
EPSS Низкий

Описание

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-activerecord-2.3removedpackage
ruby-activerecord-2.3end-of-lifewheezypackage
ruby-activerecord-3.2removedpackage
railsfixed2:4.1.4-1package
railsnot-affectedwheezypackage
railsend-of-lifesqueezepackage
rails-3.2fixed3.2.19-1package
rails-4.0removedpackage

EPSS

Процентиль: 79%
0.0125
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.

redhat
больше 11 лет назад

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.

nvd
больше 11 лет назад

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.

github
больше 8 лет назад

Active Record contains SQL Injection via improper range quoting

EPSS

Процентиль: 79%
0.0125
Низкий