Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jmm9-2p29-vh2w

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

activerecord vulnerable to SQL Injection

Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.

Пакеты

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.4

3.0.4

EPSS

Процентиль: 81%
0.02173
Низкий

Дефекты

CWE-89

Связанные уязвимости

ubuntu
больше 15 лет назад

Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.

nvd
больше 15 лет назад

Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.

debian
больше 15 лет назад

Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the ...

EPSS

Процентиль: 81%
0.02173
Низкий

Дефекты

CWE-89