Описание
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | ignored | end of life |
| devel | not-affected | |
| edgy | ignored | end of life, was needed |
| feisty | ignored | end of life, was needed |
| gutsy | not-affected | |
| hardy | not-affected | |
| intrepid | not-affected | |
| jaunty | not-affected | |
| karmic | not-affected | |
| upstream | released | 1.2.4 |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 94%
0.12046
Средний
4.3 Medium
CVSS2
Связанные уязвимости
nvd
больше 18 лет назад
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
debian
больше 18 лет назад
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord: ...
EPSS
Процентиль: 94%
0.12046
Средний
4.3 Medium
CVSS2