Логотип exploitDog
bind:CVE-2011-2197
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2011-2197

Количество 4

Количество 4

ubuntu логотип

CVE-2011-2197

больше 14 лет назад

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-2197

больше 14 лет назад

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-2197

больше 14 лет назад

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-v9v4-7jp6-8c73

около 8 лет назад

rails Cross-site Scripting vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-2197

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-2197

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-2197

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x ...

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
github логотип
GHSA-v9v4-7jp6-8c73

rails Cross-site Scripting vulnerability

0%
Низкий
около 8 лет назад

Уязвимостей на страницу