Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2008-7248

больше 16 лет назад

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2008-7248

больше 17 лет назад

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-7248

больше 16 лет назад

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2008-7248

больше 16 лет назад

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-8fqx-7pv4-3jwm

почти 9 лет назад

Improper Input Validation in actionpack

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2008-7248

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

CVSS2: 6.8
8%
Низкий
больше 16 лет назад
redhat логотип
CVE-2008-7248

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

CVSS2: 4.3
8%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-7248

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

CVSS2: 6.8
8%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-7248

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify ...

CVSS2: 6.8
8%
Низкий
больше 16 лет назад
github логотип
GHSA-8fqx-7pv4-3jwm

Improper Input Validation in actionpack

8%
Низкий
почти 9 лет назад

Уязвимостей на страницу