Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6316

Опубликовано: 07 сент. 2016
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:4.2.7.1-1package
railsnot-affectedwheezypackage
ruby-actionpack-3.2removedpackage

Примечания

  • https://github.com/rails/rails/commit/4bcccf5ecd81a6272479537911b7d9760c5be164

EPSS

Процентиль: 82%
0.01626
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.

CVSS3: 6.1
redhat
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.

CVSS3: 6.1
nvd
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.

CVSS3: 6.1
github
больше 8 лет назад

actionview Cross-site Scripting vulnerability

EPSS

Процентиль: 82%
0.01626
Низкий