Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-17916

Опубликовано: 29 дек. 2017
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
Версия до 5.1.4 (включая)

EPSS

Процентиль: 69%
0.00586
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

CVSS3: 8.1
debian
около 8 лет назад

SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5 ...

CVSS3: 8.1
github
больше 3 лет назад

** DISPUTED ** SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.

EPSS

Процентиль: 69%
0.00586
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-89